CWE-532

CWE-532 · 19 records · 10 with a public proof-of-concept

Records the NVD classes under CWE-532, highest CVSS first.

  1. HIGH 8.8CVE-2026-92918public PoC

    admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bea…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.8CVE-2026-49810

    Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclo…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.3CVE-2025-71425public PoC

    Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not custo…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.3CVE-2025-71423public PoC

    Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets …

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-92237

    Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and oth…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.3CVE-2026-95815public PoC

    OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agen…

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.3CVE-2026-73457

    Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 4.6CVE-2026-82716public PoC

    The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has complete…

    AI risk analysis on Exploit-DB.ai →

  9. LOW 3.3CVE-2026-93982public PoC

    OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encod…

    AI risk analysis on Exploit-DB.ai →

  10. LOW 3CVE-2026-73442

    On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forward…

    AI risk analysis on Exploit-DB.ai →

  11. UNSCOREDCVE-2026-63208public PoC

    Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide this token in the log, bu…

    AI risk analysis on Exploit-DB.ai →

  12. UNSCOREDCVE-2026-85417

    Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retriev…

    AI risk analysis on Exploit-DB.ai →

  13. UNSCOREDCVE-2026-14443

    Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these k…

    AI risk analysis on Exploit-DB.ai →

  14. UNSCOREDCVE-2026-14442

    An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters inclu…

    AI risk analysis on Exploit-DB.ai →

  15. UNSCOREDCVE-2026-82372

    Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can vi…

    AI risk analysis on Exploit-DB.ai →

  16. UNSCOREDCVE-2026-82371

    Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or suppo…

    AI risk analysis on Exploit-DB.ai →

  17. UNSCOREDCVE-2026-66068public PoC

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LOG_DEBUG("shutting down Shovel '~ts', ... Shovel state: ~tp", [Name, State]) formats the entire state map. The 'uris' field holds plaintext URIs after …

    AI risk analysis on Exploit-DB.ai →

  18. UNSCOREDCVE-2026-77285public PoC

    OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runner after repeated rende…

    AI risk analysis on Exploit-DB.ai →

  19. UNSCOREDCVE-2026-82723public PoC

    Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthentication.AddOn.AuditLog.…

    AI risk analysis on Exploit-DB.ai →