CWE-213Base

Exposure of Sensitive Information Due to Incompatible Policies

Draft in the CWE catalog · 32 CVEs mapped

32
CVEs mapped
4.4
Median CVSS
What it is

The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.

Recent examples
5.0cvss
CVE-2026-55425

CVE-2026-55425 - MEDIUM Severity Vulnerability

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java allows an authenticated user to request composite display fields without verifying that every selected field is readable. A user can retrieve protected values, including the password hash on a readable user record; ordinary users are limited to their own permitted records, while administrators can retrieve hashes for all users. This issue is fixed in versions 7.1.4 and 7.2.0-alpha.2.

MEDIUMno explanation yet
0%
epss
3.5cvss
CVE-2026-56538

CVE-2026-56538 - LOW Severity Vulnerability

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

LOWno explanation yet
0%
epss
6.5cvss
CVE-2026-6280

Improper Access Control in Nomysoft Informatics' Nomysem

Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-213
Abstraction
Base
Structure
Simple
Status
Draft