CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2026-0207 HIGH
Sensitive Information Logging Vulnerability in FlashBlade
CVE-2026-2401 MEDIUM
Schneider Electric PowerChute Serial Shutdown <=1.4 - Info Disclosure
CVSS 5.0
CVE-2026-34487 HIGH
Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
CVSS 7.5
CVE-2026-4901 MEDIUM
Insertion of Sesitive Information into Log File in Hydrosystem Control System
CVSS 6.5
CVE-2026-28261 HIGH
Dell Elastic Cloud Storage <=3.8.1.7 - Info Disclosure
CVSS 7.8
CVE-2026-4788 HIGH
IBM Tivoli Netcool Impact 7.1.0.0-7.1.0.37 - Sensitive Log Disclosure
CVSS 8.4
CVE-2026-27315 MEDIUM
Apache Cassandra: cqlsh history sensitive information leak
CVSS 5.5
CVE-2026-35185 HIGH
HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresses
CVSS 7.5
CVE-2026-4819 MEDIUM
Search Guard audit logs can contain under certain conditions user credentials
CVSS 4.9
CVE-2026-32982 HIGH
OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs
CVSS 7.5
CVE-2026-4957 LOW
OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file
CVSS 2.7
CVE-2026-28868 MEDIUM
iOS and iPadOS < 18.7.7 - Sensitive Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2026-20668 MEDIUM
iOS and iPadOS < 18.7.7 - Sensitive Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2026-32598 MEDIUM
OneUptime <10.0.24 - Info Disclosure
CVSS 6.5
CVE-2026-0520 LOW
Lenovo FileZ Android - Info Disclosure
CVSS 2.8
CVE-2026-20165 MEDIUM
Splunk Enterprise/Cloud - Info Disclosure
CVSS 6.3
CVE-2026-21791 LOW
HCL Sametime for Android - Info Disclosure
CVSS 3.3
CVE-2026-29184 LOW
Backstage plugin-scaffolder-backend < 3.1.4 - Sensitive Information Exposure via Log Redaction Bypass
CVSS 2.0
CVE-2026-24308 HIGH
Apache ZooKeeper 3.8.5/3.9.4 - Info Disclosure
CVSS 7.5
CVE-2026-21786 LOW
HCL Sametime for iOS - Info Disclosure
CVSS 3.3
CVE-2026-1265 MEDIUM
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Info Disclosure
CVSS 4.3
CVE-2026-27900 MEDIUM
Terraform Provider for Linode <v3.9.0 - Info Disclosure
CVSS 5.0
CVE-2026-2605 MEDIUM
Tanium TanOS 1.8.4-1.8.4.0249 - Insertion of Sensitive Information into Log File
CVSS 5.3
CVE-2026-2350 MEDIUM
Tanium Interact/TDS - Info Disclosure
CVSS 6.5
CVE-2026-1292 MEDIUM
Tanium Trends 3.10.0-3.10.19 - Insertion of Sensitive Information into Log File
CVSS 6.5
Details
Vulnerabilities 1,170
Exploit Likelihood Medium