CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2026-20144 MEDIUM
Splunk Enterprise <10.2.0 - Info Disclosure
CVSS 6.8
CVE-2026-20142 MEDIUM
Splunk Enterprise <10.2.0 - Info Disclosure
CVSS 6.8
CVE-2026-20138 MEDIUM
Splunk Enterprise <10.2.0 - Info Disclosure
CVSS 6.8
CVE-2026-20663 LOW
iPadOS < 18.7.5 - Sensitive Information Disclosure via Log File
CVSS 3.3
CVE-2026-20646 LOW
macOS Tahoe <26.3 - Info Disclosure
CVSS 3.3
CVE-2026-1495 MEDIUM
PI to CONNECT - Privilege Escalation
CVSS 6.5
CVE-2026-21222 MEDIUM
Windows 10/11 Kernel Log File Information Disclosure
CVSS 5.5
CVE-2026-25918 MEDIUM
unity-cli < 1.8.2 - Sensitive Credential Exposure in Verbose Logging
CVSS 5.5
CVE-2026-25813 HIGH
PlaciPy 1.0.0 - Sensitive Information Exposure via Console Log
CVSS 7.5
CVE-2026-25846 MEDIUM
JetBrains YouTrack <2025.3.119033 - Info Disclosure
CVSS 6.5
CVE-2026-22038 HIGH
AutoGPT <autogpt-platform-beta-v0.6.46 - Info Disclosure
CVSS 8.1
CVE-2026-1622 MEDIUM
Neo4j < 5.26.21, < 2026.01.3, < 4.4.48 - Information Disclosure in Query Log Error Handling
CVE-2026-24762 HIGH
rustfs 1.0.0-alpha.13-1.0.0-alpha.81 - Sensitive Credential Exposure in Log Files
CVSS 7.5
CVE-2026-22778 CRITICAL
vLLM 0.8.3-0.14.0 - Information Disclosure via Multimodal Endpoint Error Handling
CVSS 9.8
CVE-2026-25211 LOW
llama-stack < 0.4.0rc3 - Sensitive Information Exposure in Initialization Log
CVSS 3.2
CVE-2026-0936 MEDIUM
B&R PVI client < 6.5 - Authenticated Credential Exposure via Log File Insertion
CVSS 5.0
CVE-2026-0519 LOW
Absolute Secure Access 12.70-14.20 - Sensitive Information Exposure in Logging Subsystem
CVSS 3.4
CVE-2026-22782 HIGH
RustFS 1.0.0-alpha.1-1.0.0-alpha.79 - Sensitive Information Exposure via Invalid RPC Signature Logging
CVSS 7.5
CVE-2026-23493 HIGH
Pimcore <12.3.1-11.5.14 - Info Disclosure
CVSS 8.6
CVE-2026-20818 MEDIUM
Windows Server Information Disclosure via Log File Insertion
CVSS 6.2
CVE-2026-22798 MEDIUM
hermes 0.8.1-<0.9.1 - Sensitive Information Disclosure in Log Files via -O Argument
CVSS 5.9
CVE-2025-59868 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data exposure
CVSS 5.5
CVE-2025-46313 MEDIUM
macOS < 26.1 - Unprotected User Data Exposure via Logging Issue
CVSS 5.5
CVE-2025-13755 MEDIUM
IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase buckets
CVSS 5.5
CVE-2025-67223 HIGH
Aranda Service Desk <8.3.12 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 1,170
Exploit Likelihood Medium