CVE-2026-5025

Publication date

2026-03-27 14:43:00

Family

tenable

State

PUBLISHED

Description

The /logs and /logs-stream endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication (get_current_active_user) without any privilege checks (e.g., is_superuser).