What is CWE-532?
The product writes sensitive information to a log file.
CWE-532 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-532 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality — Read Application Data. Logging sensitive user data, full path names, or system information often provides attackers with an additional, less-protected path to acquiring the information.
Source: MITRE CWE, common consequences.
How CWE-532 is exploited in the wild
Threadlinqs maps 4 CVEs to CWE-532, published between 2025-12-09 and 2026-08-27. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 high, 3 medium. The highest EPSS score in the set is 0.1% (CVE-2026-21808), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-532 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)” (2026-09-13). Affected products concentrate in Docker (1), HCLSoftware (1), MongoDB (1), among 4 vendors in total.
Vulnerabilities (CVEs)
All 4 CVEs mapped to CWE-532, CISA KEV first, then by CVSS score.
- CVE-2025-13743 — CVSS 7.5 high · EPSS 0.0% · published 2025-12-09
- CVE-2026-81530 — CVSS 5.6 medium · EPSS 0.0% · published 2026-08-27
- CVE-2026-19363 — CVSS 5.3 medium · published 2026-08-09
- CVE-2026-21808 — CVSS 4.1 medium · EPSS 0.1% · published 2026-08-26
Affected vendors
- Docker — 1 CVE
- HCLSoftware — 1 CVE
- MongoDB — 1 CVE
- lmammino — 1 CVE
Threat activity
7 tracked threats cite CWE-532:
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)MEDIUM
- SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User RecordsHIGH
- Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)HIGH
- Acer Wave 7 Mesh Routers — Max-Severity Unauthenticated Zero-Days CVE-2026-49200 (Cleartext Credential Disclosure) & CVE-2026-49201 (Hardcoded AES Key Backdoor)CRITICAL
- Apple iOS/iPadOS Notification Services Data Retention Zero-Day (CVE-2026-28950) — Exploited In-The-Wild for Forensic Extraction of Signal MessagesHIGH
- APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs)HIGH
Mitigations
- Architecture and Design, Implementation: Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files.
- Distribution: Remove debug log files before deploying the application into production.
- Operation: Protect log files against unauthorized read/write.
- Implementation: Adjust configurations appropriately when software is transitioned from a debug state to production.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.