CVE-2026-0519

In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) En Secure Access 12.70 y previo a la 14.20, el subsistema de registro podría escribir un token de autenticación sin redactar en los registros bajo ciertas configuraciones. Cualquier parte con acceso a esos registros podría leer el token y reutilizarlo para acceder a un sistema integrado.

02 Feb 2026, 16:04

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.4
First Time Absolute secure Access
Absolute
References () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-0519 - () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-0519 - Vendor Advisory
CPE cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

20 Jan 2026, 19:15

Type Values Removed Values Added
CWE CWE-532

17 Jan 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-17 02:15

Updated : 2026-06-17 10:10


NVD link : CVE-2026-0519

Mitre link : CVE-2026-0519

CVE.ORG link : CVE-2026-0519


JSON object : View

Products Affected

absolute

  • secure_access
CWE
CWE-532

Insertion of Sensitive Information into Log File