CVE-2026-27900 describes a sensitive information exposure vulnerability in the Terraform Provider for Linode versions prior to v3.9.0, where debug logs could unredacted passwords, StackScript content, and object storage data. This issue is only exposed when debug logging is explicitly enabled. The vulnerability has a CVSS score of 5.0 (Medium), indicating a low-complexity attack requiring authenticated access to logs, potentially leading to sensitive data compromise. There is no evidence of active exploitation, public exploit code, or significant media coverage, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.9.0CPE matchmatch criteria | cpe:2.3:a:terraform:linode_provider:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.