CWE-214: Invocation of Process Using Visible Sensitive Information
A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.
29 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-74873 — openssl_encrypt before 1.4.0 Password Exposure via CLI Argument
- CVE-2024-4254 — Secrets Exfiltration in gradio-app/gradio
- CVE-2025-5452 — A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applicat
- CVE-2026-12250 — Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner
- CVE-2025-32987 — Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password
- CVE-2025-1333 — IBM MQ Operator information disclosure
- CVE-2026-76054 — Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an a
- CVE-2026-81684 — openssl_encrypt before 1.4.9 Information Disclosure via Command Line
- CVE-2025-59955 — Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint
- CVE-2025-53860 — F5OS-A FIPS HSM vulnerability
- CVE-2024-28799 — IBM QRadar Suite Software information disclosure
- CVE-2025-48709 — BMC Control-M/Server cleartext database credentials in process lists and logs
- CVE-2024-39314 — toy-blog administrative token leaked through the command line parameter
- CVE-2026-9494 — ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
- CVE-2026-80158 — Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings
- CVE-2026-65088 — NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive inf
- CVE-2026-40159 — PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution
- CVE-2026-18915 — Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
- CVE-2024-1742 — Information disclosure in mk_oracle Checkmk agent plugin
- CVE-2026-12139 — Tanium addressed an information disclosure vulnerability in Connect.
Recently published
- CVE-2026-81684 — openssl_encrypt before 1.4.9 Information Disclosure via Command Line
- CVE-2026-80158 — Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings
- CVE-2026-65088 — NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive inf
- CVE-2026-76054 — Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an a
- CVE-2026-74873 — openssl_encrypt before 1.4.0 Password Exposure via CLI Argument
- CVE-2026-18915 — Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
- CVE-2026-12139 — Tanium addressed an information disclosure vulnerability in Connect.
- CVE-2026-9494 — ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
- CVE-2026-12250 — Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner
- CVE-2026-41357 — OpenClaw < 2026.3.31 - Unsanitized Environment Variable Leakage in SSH Sandbox Backends
- CVE-2026-40159 — PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution
- CVE-2025-59955 — Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint
- CVE-2025-5452 — A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applicat
- CVE-2025-53860 — F5OS-A FIPS HSM vulnerability
- CVE-2025-48709 — BMC Control-M/Server cleartext database credentials in process lists and logs
- CVE-2025-1333 — IBM MQ Operator information disclosure
- CVE-2025-32987 — Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password
- CVE-2024-28799 — IBM QRadar Suite Software information disclosure
- CVE-2024-39314 — toy-blog administrative token leaked through the command line parameter
- CVE-2024-4254 — Secrets Exfiltration in gradio-app/gradio