CVE-2026-58070: Medium severity vulnerability
Published Aug 26, 2026
·Updated
A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.
Event History
Aug 26, 2026
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access would an attacker need to recover credentials?
The attacker would need read access to the support log on the guest OS. Users without access to that log are not described as able to retrieve the recorded credentials.
2
What credentials could be exposed through the log?
The log may contain guest OS processing credentials in cleartext, including privileged account credentials.