CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,099 vulnerabilities with CWE-532
CVE-2026-41182 MEDIUM
LangSmith SDK: Streaming token events bypass output redaction
CVSS 5.3
CVE-2026-40945 HIGH
Oxia: Bearer token exposed in debug log messages on authentication failure
CVE-2026-23775 HIGH
Dell PowerProtect Data Domain <8.6.0.0 - Info Disclosure
CVSS 7.6
CVE-2026-34164 MEDIUM
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
CVSS 4.9
CVE-2026-31987 HIGH
Apache Airflow: JWT token appearing in logs
CVSS 7.5
CVE-2026-20205 HIGH
Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app
CVSS 7.2
CVE-2026-40091 MEDIUM
SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
CVSS 6.0
CVE-2026-32218 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-32217 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-32215 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-0207 HIGH
Sensitive Information Logging Vulnerability in FlashBlade
CVE-2026-2401 MEDIUM
Schneider Electric PowerChute Serial Shutdown <=1.4 - Info Disclosure
CVSS 5.0
CVE-2026-34487 HIGH
Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
CVSS 7.5
CVE-2026-4901 MEDIUM
Insertion of Sesitive Information into Log File in Hydrosystem Control System
CVSS 6.5
CVE-2026-28261 HIGH
Dell Elastic Cloud Storage <=3.8.1.7 - Info Disclosure
CVSS 7.8
CVE-2026-4788 HIGH
Multiple Vulnerabilities affect IBM Tivoli Netcool Impact
CVSS 8.4
CVE-2026-27315 MEDIUM
Apache Cassandra: cqlsh history sensitive information leak
CVSS 5.5
CVE-2026-35185 HIGH
HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresses
CVSS 7.5
CVE-2026-4819 MEDIUM
Search Guard audit logs can contain under certain conditions user credentials
CVSS 4.9
CVE-2026-32982 HIGH
OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs
CVSS 7.5
CVE-2026-5128 CRITICAL
ArthurFiorette steam-trader 2.1.1 - Info Disclosure
CVSS 10.0
CVE-2026-4957 LOW
OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file
CVSS 2.7
CVE-2026-28868 MEDIUM
Apple Ios And Ipados < 18.7.7 - Denial of Service
CVSS 5.5
CVE-2026-20668 MEDIUM
Apple Ios And Ipados < 18.7.7 - Denial of Service
CVSS 5.5
CVE-2026-32598 MEDIUM
OneUptime <10.0.24 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 1,099
Exploit Likelihood Medium