CVE-2026-0519 – 4.8, Medium

Information disclosure vulnerability in Secure Access Server prior to version 14.20.

Last updated: January 13th, 2026

CVE-2026-0519 - In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuseit to access an integrated system.

https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N