CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2026-35185 HIGH
HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresses
CVSS 7.5
CVE-2026-4819 MEDIUM
Search Guard audit logs can contain under certain conditions user credentials
CVSS 4.9
CVE-2026-32982 HIGH
OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs
CVSS 7.5
CVE-2026-4957 LOW
OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file
CVSS 2.7
CVE-2026-28868 MEDIUM
iOS and iPadOS < 18.7.7 - Sensitive Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2026-20668 MEDIUM
iOS and iPadOS < 18.7.7 - Sensitive Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2026-32598 MEDIUM
OneUptime <10.0.24 - Info Disclosure
CVSS 6.5
CVE-2026-0520 LOW
Lenovo FileZ Android - Info Disclosure
CVSS 2.8
CVE-2026-20165 MEDIUM
Splunk Enterprise/Cloud - Info Disclosure
CVSS 6.3
CVE-2026-21791 LOW
HCL Sametime for Android - Info Disclosure
CVSS 3.3
CVE-2026-29184 LOW
Backstage plugin-scaffolder-backend < 3.1.4 - Sensitive Information Exposure via Log Redaction Bypass
CVSS 2.0
CVE-2026-24308 HIGH
Apache ZooKeeper 3.8.5/3.9.4 - Info Disclosure
CVSS 7.5
CVE-2026-21786 LOW
HCL Sametime for iOS - Info Disclosure
CVSS 3.3
CVE-2026-1265 MEDIUM
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Info Disclosure
CVSS 4.3
CVE-2026-27900 MEDIUM
Terraform Provider for Linode <v3.9.0 - Info Disclosure
CVSS 5.0
CVE-2026-2605 MEDIUM
Tanium TanOS 1.8.4-1.8.4.0249 - Insertion of Sensitive Information into Log File
CVSS 5.3
CVE-2026-2350 MEDIUM
Tanium Interact/TDS - Info Disclosure
CVSS 6.5
CVE-2026-1292 MEDIUM
Tanium Trends 3.10.0-3.10.19 - Insertion of Sensitive Information into Log File
CVSS 6.5
CVE-2026-20144 MEDIUM
Splunk Enterprise <10.2.0 - Info Disclosure
CVSS 6.8
CVE-2026-20142 MEDIUM
Splunk Enterprise <10.2.0 - Info Disclosure
CVSS 6.8
CVE-2026-20138 MEDIUM
Splunk Enterprise <10.2.0 - Info Disclosure
CVSS 6.8
CVE-2026-20663 LOW
iPadOS < 18.7.5 - Sensitive Information Disclosure via Log File
CVSS 3.3
CVE-2026-20646 LOW
macOS Tahoe <26.3 - Info Disclosure
CVSS 3.3
CVE-2026-1495 MEDIUM
PI to CONNECT - Privilege Escalation
CVSS 6.5
CVE-2026-21222 MEDIUM
Windows 10/11 Kernel Log File Information Disclosure
CVSS 5.5
Details
Vulnerabilities 1,137
Exploit Likelihood Medium