CVEPublished 2026-08-30Modified 2026-09-010 articles on news4 live referencesNVD data

CVE-2026-77970

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
1
Exploit Prediction Scoring System · top 99% of all CVEs
Description

Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore only act on the tracked resource's top-level attributes. maybe_redact_changes/3 and the stored-action-input path in AshPaperTrail.Resource.Changes.CreateNewVersion derive the sensitive set from the resource's own attributes and never descend into embedded, union, or list values, so a non-sensitive attribute or action argument that holds an embed with a sensitive? field (for example an accepted credentials embed carrying a token) is written to the version table in cleartext. This issue affects ash_paper_trail: from 0.3.0 before 0.7.0.

Timeline
Published 2026-08-30
Modified 2026-09-01

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-77970 on GitHub.
We haven't classified any articles referencing CVE-2026-77970 yet. The external references above still apply.