CVE-2025-36328
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed techn
CVSS
4.3
Medio
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Publicado: 30 jun 2026 · Última mod.: 6 jul 2026 · CWE-209
0.2%EPSS · 30 días0.4%
2026-08-202026-09-18
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-553755.3 MED16.8%
——5canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing access logs, proxy logs, and APM traces to persist the credentials in plaintext. When a token request fails, OAuth2::obtainAccessToken() also passes the credential-bearing Guzzle request URI into AuthorizationFailedException, so application logs and error trackers can record the same secrets. An attacker with access to affected telemetry can obtain Canto credentials and use them to request access tokens for the tenant. This issue is fixed in version 3.0.0.3dCVE-2026-55102—1.7%
——1hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response configuration. These objects can contain the X-Vault-Token request header and err.config.data request body, including submitted passwords or secret values. When a consuming application records the caught exception through console logging, structured loggers, monitoring, crash reporting, or an application performance monitoring service, the live Vault token and request secrets can be stored in plaintext and exposed to anyone with access to that output. A stolen token can permit unauthorized access to the Vault instance under the token's policies. This issue is fixed in version 0.5.2.4dCVE-2026-663066.5 MED42.0%
——13Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.2dCVE-2026-696845.5 MED39.7%
——12Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.10dCVE-2026-695525.7 MED57.9%
——17Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.1dCVE-2026-692945.5 MED27.6%
——8Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.1d