CWE•Base•Incomplete•20 recent CVEs
CWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere
Description
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
[object Object]
Common consequences
- Confidentiality→Read Application Data
Potential mitigations
- Architecture and Design,ImplementationProduction applications should never use methods that generate internal details such as stack traces and error messages unless that information is directly committed to a log that is not viewable by the end user. All error message text should be HTML entity encoded before being written to the log file to protect against potential cross-site scripting attacks against the viewer of the logs
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-971815.32026-09-24CVE-2026-847125.32026-09-23CVE-2026-956005.32026-09-23CVE-2025-331416.52026-09-18CVE-2026-275536.52026-09-16CVE-2026-380588.12026-09-11CVE-2026-619114.32026-09-09CVE-2026-813945.52026-09-08CVE-2026-813875.52026-09-08CVE-2026-713307.52026-09-08CVE-2026-698325.62026-09-08CVE-2026-697235.72026-09-08CVE-2026-694065.52026-09-08CVE-2026-693395.52026-09-08CVE-2026-693155.52026-09-08CVE-2026-688425.52026-09-08CVE-2026-160062026-09-08CVE-2026-769686.52026-09-08CVE-2026-801197.82026-09-04CVE-2026-801187.12026-09-04