CWE-526: Cleartext Storage of Sensitive Information in an Environment Variable
The product uses an environment variable to store unencrypted sensitive information.
19 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-36017 — IBM Controller Information Disclosure
- CVE-2026-45370 — python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
- CVE-2026-40153 — PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
- CVE-2026-76227 — Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
- CVE-2025-0985 — IBM MQ information disclosure
- CVE-2026-72648 — Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure
- CVE-2024-12604 — Improper Authentication in Tapandsign Technologies Tap and Sign App
- CVE-2025-27899 — Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
- CVE-2025-36105 — IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive information disclosure vulnerability
- CVE-2026-49377 — In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
Recently published
- CVE-2026-76227 — Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
- CVE-2026-72648 — Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure
- CVE-2026-49377 — In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
- CVE-2026-45370 — python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
- CVE-2026-40153 — PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
- CVE-2025-36105 — IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive information disclosure vulnerability
- CVE-2025-27899 — Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
- CVE-2025-36017 — IBM Controller Information Disclosure
- CVE-2024-12604 — Improper Authentication in Tapandsign Technologies Tap and Sign App
- CVE-2025-0985 — IBM MQ information disclosure