Threats Tagged 'cwe-526'
View all threats tagged with 'cwe-526'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-526'
Click on any threat for detailed analysis and mitigation recommendations
0 Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server resource that authenticates to Elasticsearch with a service account token, the token is written into the generated workload specification in cleartext rather than being referenced from the Kubernetes Secret that ECK maintains for the other credentials on the same path. Any principal able to read workload specifications in the affected namespace can therefore read a live Elasticsearch credential, even when Kubernetes RBAC does not grant that principal access to Secrets. Join the discussion | CVE Database V5 | 08/13/2026, 19:13:31 UTC Added: 08/13/2026, 19:26:57 UTC |
0 CVE-2026-49377 is a medium severity vulnerability in JetBrains TeamCity before version 2025.11.2. It involves the exposure of sensitive data through default agent parameters. The vulnerability is identified as CWE-526, which relates to exposure of sensitive information. There is no official patch or remediation level provided yet, and no known exploits in the wild have been reported. The CVSS score is 4.3, indicating a medium impact primarily due to confidentiality loss without impact on integrity or availability. Join the discussion | CVE Database V5 | 05/29/2026, 18:15:50 UTC Added: 05/29/2026, 18:33:50 UTC |
python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. When combined with CVE-2026-45369, an attacker can exfiltrate all process-level secrets in a single tool call. This vulnerability is fixed in 1.1.3. Join the discussion | CVE Database V5 | 05/14/2026, 20:14:20 UTC Added: 05/14/2026, 20:51:38 UTC |
0 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using shell=False (line 88) for security. This allows exfiltration of secrets stored in environment variables (database credentials, API keys, cloud access keys). The approval system displays the unexpanded $VAR references to human reviewers, creating a deceptive approval where the displayed command differs from what actually executes. This vulnerability is fixed in 1.5.128. Join the discussion | CVE Database V5 | 04/09/2026, 21:27:45 UTC Added: 04/10/2026, 00:25:27 UTC |
IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables. Join the discussion | CVE Database V5 | 03/10/2026, 00:50:05 UTC Added: 03/10/2026, 01:19:14 UTC |
0 IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system. Join the discussion | CVE Database V5 | 02/17/2026, 19:50:33 UTC Added: 02/18/2026, 08:18:01 UTC |
0 IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user. Join the discussion | CVE Database V5 | 12/08/2025, 21:37:10 UTC Added: 12/08/2025, 21:45:29 UTC |
0 Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse. This issue affects Tap&Sign App: before V.1.025. Join the discussion | CVE Database V5 | 03/10/2025, 14:28:12 UTC Added: 06/01/2026, 15:03:54 UTC |
0 IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that could be obtained by a local user. Join the discussion | CVE Database V5 | 02/28/2025, 16:21:35 UTC Added: 08/26/2025, 20:02:50 UTC |
0 A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing. Join the discussion | CVE Database V5 | 01/14/2025, 08:36:08 UTC Added: 11/20/2025, 18:33:15 UTC |
Showing 1 to 10 of 10 results