CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,169 vulnerabilities with CWE-532
CVE-2026-12947 HIGH
IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodes
CVSS 7.5
CVE-2026-44105 MEDIUM
Phoenix Contact CHARX SEC-3150 - Cleartext Password in Logs
CVSS 6.6
CVE-2026-59326 LOW
HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server
CVSS 3.3
CVE-2026-14528 HIGH
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
CVSS 7.4
CVE-2026-1918 MEDIUM
IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file
CVSS 4.9
CVE-2026-64800 LOW
Jetbrains GoLand < 2026.2 - Insertion of Sensitive Information into Log File
CVSS 3.5
CVE-2026-65589 MEDIUM
n8n before 1.123.64 Credential Exposure via LLM Node Execution Data
CVSS 6.5
CVE-2026-62211 MEDIUM
OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export
CVSS 5.0
CVE-2026-46514 MEDIUM
Frogman: Plaintext passwords and secrets persisted to audit log
CVSS 6.5
CVE-2026-44969 LOW
dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabled
CVSS 2.5
CVE-2026-15737 MEDIUM
Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
CVSS 5.7
CVE-2026-40633 HIGH
Dell PowerScale OneFS - Insertion of Sensitive Information into Log File
CVSS 7.8
CVE-2026-50316 MEDIUM
Microsoft Windows 10 Version 21H2 - Windows Kernel Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-22098 CRITICAL
Sensitive information is written to logs
CVE-2026-56459 MEDIUM
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure
CVSS 6.2
CVE-2026-59947 MEDIUM
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
CVSS 4.7
CVE-2026-54652 HIGH
Frigate viewer can read logs exposing admin and camera credentials
CVSS 8.1
CVE-2026-46467 MEDIUM
Dell PowerProtect Data Domain - Insertion of Sensitive Information into Log File
CVSS 5.8
CVE-2026-8482 MEDIUM
Stormshield Network Security - Information Leak in NSRPC Client History
CVSS 4.3
CVE-2026-54704 MEDIUM
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
CVSS 6.5
CVE-2026-49088 MEDIUM
Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosure
CVSS 4.4
CVE-2026-12086 MEDIUM
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability
CVSS 6.2
CVE-2026-13750 MEDIUM
Snowflake CLI Sensitive Credential Exposure Through Debug Logging
CVSS 5.5
CVE-2026-56457 MEDIUM
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information
CVSS 4.3
CVE-2026-9699 MEDIUM
Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication errors
CVSS 6.8
Details
Vulnerabilities 1,169
Exploit Likelihood Medium