CVE-2026-82723P4LOWCVSS 1.8≥ 4.12.0, < 4.15.0·≥ 5.0.0-rc.0, < 5.0.0-rc.2+1 more2026-09-17
CVE-2026-82723 [LOW] CWE-532 CVE-2026-82723: Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication all
Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store.
The audit_log add-on builds each entry's extra_data in AshAuthentication.AddOn.AuditLog.Auditor.build_extra_data/4, which takes :actor from the action callback context verbatim. Any
nvd