CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,169 vulnerabilities with CWE-532
CVE-2026-8330 MEDIUM
Insertion of Sensitive Information into Log File in GitLab
CVSS 4.4
CVE-2026-12053 HIGH
Insertion of Sensitive Information into Log File in GitLab
CVSS 8.6
CVE-2026-9073 MEDIUM
Foreman-mcp-server: mcp server: insecure sensitive http header sanitization
CVSS 6.2
CVE-2026-11820 MEDIUM
Ansible community.general nexmo - API Credentials Exposed in GET URL
CVSS 6.5
CVE-2026-11819 MEDIUM
Community.general: community.general keyring_info — os keyring passphrase returned in plaintext
CVSS 5.5
CVE-2026-54236 MEDIUM
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
CVSS 5.3
CVE-2026-0267 MEDIUM
GlobalProtect App: Information Exposure Vulnerability on macOS
CVSS 5.5
CVE-2026-9751 MEDIUM
Sensitive data could be written to mongod.log
CVSS 5.5
CVE-2026-9735 MEDIUM
Keyfile contents are in MongoDB Server logs
CVSS 5.5
CVE-2026-45581 MEDIUM
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
CVSS 5.5
CVE-2026-50205 HIGH
Acer Connect M6E 5G Portable WiFi Router - Plaintext Log Credential Leakage
CVSS 8.2
CVE-2026-45679 MEDIUM
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
CVSS 6.5
CVE-2026-40619 HIGH
Genetec Security Center - Insertion of Sensitive Information into Log File
CVSS 7.8
CVE-2026-49200 CRITICAL
Acer Wave 7 router: Broken Access Control
CVSS 9.8
CVE-2026-45040 MEDIUM
RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]
CVE-2026-6720 HIGH
Calicoctl leaks cluster credentials to stderr when verbose logging is enabled
CVE-2026-41185 MEDIUM
ServiceAccount token disclosure via Azure IPAM CNI plugin logs
CVSS 6.5
CVE-2026-41184 MEDIUM
Tigera Calico - ServiceAccount Token Disclosure via Install-Cni Container Logs
CVSS 6.5
CVE-2026-32996 HIGH
Veeam Backup And Replication < 13.0.1 - Insertion of Sensitive Information into Log File
CVE-2026-5515 MEDIUM
IBM App Connect Enterprise is vulnerable to a confidential disclosure
CVSS 5.5
CVE-2026-2607 MEDIUM
Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
CVSS 5.1
CVE-2026-25193 HIGH
Gallagher Command Centre Server - Insertion of Sensitive Information into Log File
CVSS 8.1
CVE-2026-8671 HIGH
Log Files contain encrypted secrets
CVSS 7.5
CVE-2026-44052 HIGH
Netatalk 2.1.0-4.4.2 - Sensitive Information Disclosure via LDAP Password Logging
CVSS 7.5
CVE-2026-20239 HIGH
Sensitive Information Disclosure through Log Files in Splunk Enterprise
CVSS 7.5
Details
Vulnerabilities 1,169
Exploit Likelihood Medium