CVE-2026-11820
Severity CVSS v4.0:
Pending analysis
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
23/06/2026
Last modified:
01/07/2026
Description
A flaw was found in the community.general Ansible collection&#39;s nexmo module.<br />
The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding<br />
API credentials (api_key and api_secret) into URL query parameters and<br />
sending them via GET requests. This causes credentials to be exposed in web<br />
server access logs, proxy logs, HTTP Referer headers, and network monitoring<br />
tools, despite the Ansible argument specification marking these parameters<br />
as no_log. An attacker with access to any of these logging or monitoring<br />
points can obtain the full API credentials and gain unauthorized access to<br />
the victim&#39;s Vonage/Nexmo account.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



