Threadlinqs IntelligenceStart free

Weakness · BaseCWE-532

CWE-532: Insertion of Sensitive Information into Log File

Likelihood of exploit: MediumBase

As of 2026-10-05, CWE-532 (Insertion of Sensitive Information into Log File) underlies 4 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 7 tracked threats. MITRE rates its likelihood of exploit as Medium.

CVEs
4Mapped to CWE-532
CISA KEV
0None listed yet
Critical
0CVSS v3 critical CVEs
Threats
7Tracked campaigns citing it
Likelihood
MediumMITRE likelihood of exploit

Last updated:

What is CWE-532?

The product writes sensitive information to a log file.

CWE-532 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-532 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality — Read Application Data. Logging sensitive user data, full path names, or system information often provides attackers with an additional, less-protected path to acquiring the information.

Source: MITRE CWE, common consequences.

How CWE-532 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-532, published between 2025-12-09 and 2026-08-27. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 high, 3 medium. The highest EPSS score in the set is 0.1% (CVE-2026-21808), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-532 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)” (2026-09-13). Affected products concentrate in Docker (1), HCLSoftware (1), MongoDB (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-532, CISA KEV first, then by CVSS score.

Affected vendors

  • Docker — 1 CVE
  • HCLSoftware — 1 CVE
  • MongoDB — 1 CVE
  • lmammino — 1 CVE

Threat activity

7 tracked threats cite CWE-532:

Mitigations

  • Architecture and Design, Implementation: Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files.
  • Distribution: Remove debug log files before deploying the application into production.
  • Operation: Protect log files against unauthorized read/write.
  • Implementation: Adjust configurations appropriately when software is transitioned from a debug state to production.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.