CWE•Base•Incomplete•20 recent CVEs
CWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere
Description
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
[object Object]
Common consequences
- Confidentiality→Read Application Data
Potential mitigations
- Architecture and Design,ImplementationProduction applications should never use methods that generate internal details such as stack traces and error messages unless that information is directly committed to a log that is not viewable by the end user. All error message text should be HTML entity encoded before being written to the log file to protect against potential cross-site scripting attacks against the viewer of the logs
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-582464.32026-07-28CVE-2026-664385.32026-07-27CVE-2026-655645.32026-07-27CVE-2026-595487.52026-07-27CVE-2026-595287.52026-07-27CVE-2025-591782026-07-27CVE-2026-449555.32026-07-23CVE-2026-286988.62026-07-23CVE-2026-655354.32026-07-23CVE-2026-655215.32026-07-23CVE-2026-655055.32026-07-23CVE-2026-654985.32026-07-23CVE-2026-654905.32026-07-23CVE-2026-654745.32026-07-23CVE-2026-654584.32026-07-23CVE-2026-619456.52026-07-23CVE-2023-375077.52026-07-21CVE-2026-105884.42026-07-16CVE-2026-502946.22026-07-14CVE-2026-619775.32026-07-13