CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
3,547 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-27604 — FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity
- CVE-2026-55500 — 9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover
- CVE-2026-52855 — Wings exposes node configuration secrets through egg configuration-file templating
- CVE-2026-64874 — Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension
- CVE-2026-71424 — Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers
- CVE-2026-55447 — Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
- CVE-2026-87541 — Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the
- CVE-2026-78960 — Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin
- CVE-2026-87593 — Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive inform
- CVE-2026-87565 — Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak se
- CVE-2026-87545 — Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social
- CVE-2026-87490 — Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain se
- CVE-2026-87477 — Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information
- CVE-2026-87454 — Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain
- CVE-2026-87437 — Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive informati
- CVE-2026-79293 — Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive info
- CVE-2026-79291 — Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informatio
- CVE-2026-79271 — Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering
- CVE-2026-79246 — Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i
Recently published
- CVE-2026-88013 — rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-88893 — OpenPanel Unauthenticated Share Lookup Information Disclosure
- CVE-2026-88876 — AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD
- CVE-2026-88874 — AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication Bypass
- CVE-2026-0305 — Prisma Access Agent: Information Disclosure Vulnerability on Linux
- CVE-2026-87017 — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-86767 — Snipe-IT before 8.7.0 Cross-Company Read via requested-assets
- CVE-2026-87820 — CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner
- CVE-2026-87810 — Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock
- CVE-2026-87032 — Tanium addressed an information disclosure vulnerability in Tanium Server.
- CVE-2026-87035 — Tanium addressed an information disclosure vulnerability in Comply.
- CVE-2026-87593 — Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive inform
- CVE-2026-87437 — Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive informati
- CVE-2026-87477 — Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information
- CVE-2026-87461 — Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via
- CVE-2026-87490 — Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain se
- CVE-2026-87565 — Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak se
- CVE-2026-87545 — Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social
- CVE-2026-87531 — Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rende
- CVE-2026-87435 — Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromise
More specific weaknesses
- CWE-1273 — Device Unlock Credential Sharing
- CWE-1295 — Debug Messages Revealing Unnecessary Information
- CWE-1431 — Driving Intermediate Cryptographic State/Results to Hardware Module Outputs
- CWE-201 — Insertion of Sensitive Information Into Sent Data
- CWE-203 — Observable Discrepancy
- CWE-209 — Generation of Error Message Containing Sensitive Information
- CWE-213 — Exposure of Sensitive Information Due to Incompatible Policies
- CWE-215 — Insertion of Sensitive Information Into Debugging Code
- CWE-359 — Exposure of Private Personal Information to an Unauthorized Actor
- CWE-497 — Exposure of Sensitive System Information to an Unauthorized Control Sphere
- CWE-538 — Insertion of Sensitive Information into Externally-Accessible File or Directory