Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27900

27
FAUCET Score

CVE-2026-27900 describes a sensitive information exposure vulnerability in the Terraform Provider for Linode versions prior to v3.9.0, where debug logs could unredacted passwords, StackScript content, and object storage data. This issue is only exposed when debug logging is explicitly enabled. The vulnerability has a CVSS score of 5.0 (Medium), indicating a low-complexity attack requiring authenticated access to logs, potentially leading to sensitive data compromise. There is no evidence of active exploitation, public exploit code, or significant media coverage, though it has received some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.9.0CPE matchmatch criteria
cpe:2.3:a:terraform:linode_provider:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
38.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 27th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/linode/terraform-provider-linode/v3Fixed in: 3.9.0

Vendor Advisories (1)

goGHSA-5rc7-2jj6-mp64medium

Terraform Provider for Linode Debug Logs Vulnerable to Sensitive Information Exposure

Feb 26, 2026

References

openwall.com / lists/oss-security/2026/02/26/2
Third Party Advisory
github.com / linode/terraform-provider-linode/commit/43a925d826b999f0355de3dc7330c55f496824c0
Patch
github.com / linode/terraform-provider-linode/pull/2269
Issue TrackingPatch
github.com / linode/terraform-provider-linode/releases/tag/v3.9.0
Release Notes
github.com / linode/terraform-provider-linode/security/advisories/GHSA-5rc7-2jj6-mp64
Vendor Advisory