CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2026-20239 HIGH
Sensitive Information Disclosure through Log Files in Splunk Enterprise
CVSS 7.5
CVE-2026-44516 HIGH
Valtimo: Sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
CVSS 7.6
CVE-2026-44479 MEDIUM
Vercel: Non-interactive mode includes CLI arguments in suggested command output
CVSS 5.5
CVE-2026-41219 MEDIUM
F5 BIG-IP QKView - Sensitive Information Disclosure
CVSS 6.5
CVE-2026-8200 LOW
Schema validation log messages may not redact user data
CVSS 2.7
CVE-2026-43992 CRITICAL
JunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameter
CVSS 9.8
CVE-2026-28987 HIGH
iOS and iPadOS < 18.7.9 - Sensitive Kernel State Exposure via Log File
CVSS 7.5
CVE-2026-28943 HIGH
iOS and iPadOS < 18.7.9 - Sensitive Information Exposure via Log File Insertion
CVSS 7.5
CVE-2026-28923 HIGH
macOS < 14.8.7, < 15.7.7, < 26.5 - Sensitive Information Exposure via Log File Insertion
CVSS 8.8
CVE-2026-43826 MEDIUM
Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL
CVSS 6.5
CVE-2026-41018 MEDIUM
Apache Airflow Providers Elasticsearch: Elasticsearch task-log handler leaks credentials embedded in the host URL
CVSS 6.5
CVE-2026-42282 MEDIUM
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
CVSS 4.3
CVE-2026-41495 MEDIUM
n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
CVSS 5.3
CVE-2026-41004 MEDIUM
Spring Cloud Config Sensitive Information Exposure in Trace Logs
CVSS 4.4
CVE-2026-7824 MEDIUM
PaperCut Hive (Ricoh): Plain text password in logs
CVE-2026-41182 MEDIUM
LangSmith SDK: Streaming token events bypass output redaction
CVSS 5.3
CVE-2026-40945 HIGH
Oxia: Bearer token exposed in debug log messages on authentication failure
CVE-2026-23775 HIGH
Dell PowerProtect Data Domain <8.6.0.0 - Info Disclosure
CVSS 7.6
CVE-2026-34164 MEDIUM
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
CVSS 4.9
CVE-2026-31987 HIGH
Apache Airflow: JWT token appearing in logs
CVSS 7.5
CVE-2026-20205 HIGH
Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app
CVSS 7.2
CVE-2026-40091 MEDIUM
SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
CVSS 6.0
CVE-2026-32218 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-32217 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-32215 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVSS 5.5
Details
Vulnerabilities 1,170
Exploit Likelihood Medium