CWE-213: Exposure of Sensitive Information Due to Incompatible Policies
The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.
31 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-24316 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible Policies
- CVE-2026-6280 — Improper Access Control in Nomysoft Informatics' Nomysem
- CVE-2024-49354 — IBM Concert information disclosure
- CVE-2025-4976 — Exposure of Sensitive Information Due to Incompatible Policies in GitLab
- CVE-2025-32791 — Permission policy information leakage in Backstage permission system
- CVE-2026-55425 — Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fields
- CVE-2024-49827 — IBM Concert Software information disclosure
- CVE-2025-52603 — HCL Connections is vulnerable to information disclosure
- CVE-2026-56538 — HCL Connections is vulnerable to information disclosure
- CVE-2025-54831 — Apache Airflow: Connection sensitive details exposed to users with READ permissions
Recently published
- CVE-2026-55425 — Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fields
- CVE-2026-56538 — HCL Connections is vulnerable to information disclosure
- CVE-2026-6280 — Improper Access Control in Nomysoft Informatics' Nomysem
- CVE-2025-52603 — HCL Connections is vulnerable to information disclosure
- CVE-2025-54831 — Apache Airflow: Connection sensitive details exposed to users with READ permissions
- CVE-2024-49827 — IBM Concert Software information disclosure
- CVE-2025-4976 — Exposure of Sensitive Information Due to Incompatible Policies in GitLab
- CVE-2025-32791 — Permission policy information leakage in Backstage permission system
- CVE-2025-24316 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible Policies
- CVE-2024-49354 — IBM Concert information disclosure