CWE•Base•Incomplete•20 recent CVEs
CWE-532Insertion of Sensitive Information into Log File
Description
The product writes sensitive information to a log file.
Common consequences
- Confidentiality→Read Application DataLogging sensitive user data, full path names, or system information often provides attackers with an additional, less-protected path to acquiring the information.
Potential mitigations
- Architecture and Design,ImplementationConsider seriously the sensitivity of the information written into log files. Do not write secrets into the log files.
- DistributionRemove debug log files before deploying the application into production.
- OperationProtect log files against unauthorized read/write.
- ImplementationAdjust configurations appropriately when software is transitioned from a debug state to production.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-879937.72026-09-10CVE-2026-888837.72026-09-10CVE-2026-801693.32026-09-09CVE-2026-799663.32026-09-09CVE-2025-468086.82026-09-09CVE-2026-801245.52026-09-09CVE-2026-786315.32026-09-08CVE-2026-786277.32026-09-08CVE-2026-688735.52026-09-08CVE-2026-865976.52026-09-08CVE-2026-865012.82026-09-07CVE-2026-800565.52026-09-07CVE-2026-174425.12026-09-04CVE-2026-166896.22026-09-04CVE-2026-196496.22026-09-04CVE-2026-851748.82026-09-03CVE-2026-851712026-09-03CVE-2026-552216.52026-09-02CVE-2026-557853.72026-08-28CVE-2026-781742026-08-28