In Secure Access 12.70 and prior to 14.20, the logging
subsystem may write an unredacted authentication token to logs under
certain configurations. Any party with access to those logs could read
the token and reuse it to access an integrated system.
References
| Link | Resource |
|---|---|
| https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-0519 | Vendor Advisory |
Configurations
History
02 Feb 2026, 16:04
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Absolute secure Access
Absolute |
|
| References | () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-0519 - Vendor Advisory | |
| CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.4 |
20 Jan 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-532 |
17 Jan 2026, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-17 02:15
Updated : 2026-02-02 16:04
NVD link : CVE-2026-0519
Mitre link : CVE-2026-0519
CVE.ORG link : CVE-2026-0519
JSON object : View
Products Affected
absolute
- secure_access
CWE
CWE-532
Insertion of Sensitive Information into Log File
