CWE-532
Medium likelihoodInsertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
1,137 vulnerabilities with CWE-532
CVE-2026-0267
MEDIUM
GlobalProtect App: Information Exposure Vulnerability on macOS
CVE-2026-9751
MEDIUM
Sensitive data could be written to mongod.log
CVSS 5.5
CVE-2026-9735
MEDIUM
Keyfile contents are in MongoDB Server logs
CVSS 5.5
CVE-2026-45581
MEDIUM
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
CVSS 5.5
CVE-2026-50205
HIGH
Acer Connect M6E 5G Portable WiFi Router - Plaintext Log Credential Leakage
CVSS 8.2
CVE-2026-45679
MEDIUM
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
CVSS 6.5
CVE-2026-40619
HIGH
Genetec Security Center - Insertion of Sensitive Information into Log File
CVSS 7.8
CVE-2026-49200
CRITICAL
Acer Wave 7 router: Broken Access Control
CVSS 9.8
CVE-2026-45040
MEDIUM
RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]
CVE-2026-6720
HIGH
Calicoctl leaks cluster credentials to stderr when verbose logging is enabled
CVE-2026-41185
MEDIUM
ServiceAccount token disclosure via Azure IPAM CNI plugin logs
CVSS 6.5
CVE-2026-41184
MEDIUM
Tigera Calico - ServiceAccount Token Disclosure via Install-Cni Container Logs
CVSS 6.5
CVE-2026-32996
HIGH
Veeam Backup And Replication < 13.0.1 - Insertion of Sensitive Information into Log File
CVE-2026-5515
MEDIUM
IBM App Connect Enterprise is vulnerable to a confidential disclosure
CVSS 5.5
CVE-2026-2607
MEDIUM
Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
CVSS 5.1
CVE-2026-25193
HIGH
Gallagher Command Centre Server - Insertion of Sensitive Information into Log File
CVSS 8.1
CVE-2026-8671
HIGH
Log Files contain encrypted secrets
CVSS 7.5
CVE-2026-44052
HIGH
Netatalk 2.1.0-4.4.2 - Sensitive Information Disclosure via LDAP Password Logging
CVSS 7.5
CVE-2026-20239
HIGH
Sensitive Information Disclosure through Log Files in Splunk Enterprise
CVSS 7.5
CVE-2026-44516
HIGH
Valtimo: Sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
CVSS 7.6
CVE-2026-44479
MEDIUM
Vercel: Non-interactive mode includes CLI arguments in suggested command output
CVSS 5.5
CVE-2026-41219
MEDIUM
F5 BIG-IP QKView - Sensitive Information Disclosure
CVSS 6.5
CVE-2026-8200
LOW
Schema validation log messages may not redact user data
CVSS 2.7
CVE-2026-43992
CRITICAL
JunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameter
CVSS 9.8
CVE-2026-28987
HIGH
iOS and iPadOS < 18.7.9 - Sensitive Kernel State Exposure via Log File
CVSS 7.5
Details
Vulnerabilities
1,137
Exploit Likelihood
Medium