In Secure Access 12.70 and prior to 14.20, the logging
subsystem may write an unredacted authentication token to logs under
certain configurations. Any party with access to those logs could read
the token and reuse it to access an integrated system.
Metrics
Affected Vendors & Products
References
History
Tue, 20 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-532 | |
| Metrics |
ssvc
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Absolute
Absolute secure Access |
|
| Vendors & Products |
Absolute
Absolute secure Access |
Sat, 17 Jan 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated system. | |
| Title | Information Disclosure in Secure Access Between 12.70 and 14.20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Absolute
Published: 2026-01-17T01:13:59.183Z
Updated: 2026-01-20T18:39:13.845Z
Reserved: 2025-12-12T17:25:37.542Z
Link: CVE-2026-0519
Updated: 2026-01-20T18:38:31.687Z
Status : Received
Published: 2026-01-17T02:15:49.627
Modified: 2026-01-20T19:15:50.020
Link: CVE-2026-0519
No data.