THREAT OPS › Threat News › [NVD] CVE-2026-7860 — A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain
[NVD] CVE-2026-7860 — A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain
CVE-2026-7860 CVSS: None Published: 2026-05-19T12:16:19.960
A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any failed frontend build
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-7860cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-7860