CVE-2026-11820
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-532
Exposición de información a través de archivos de log
Fecha de publicación:
23/06/2026
Última modificación:
01/07/2026
Descripción
*** Pendiente de traducción *** A flaw was found in the community.general Ansible collection&#39;s nexmo module.<br />
The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding<br />
API credentials (api_key and api_secret) into URL query parameters and<br />
sending them via GET requests. This causes credentials to be exposed in web<br />
server access logs, proxy logs, HTTP Referer headers, and network monitoring<br />
tools, despite the Ansible argument specification marking these parameters<br />
as no_log. An attacker with access to any of these logging or monitoring<br />
points can obtain the full API credentials and gain unauthorized access to<br />
the victim&#39;s Vonage/Nexmo account.
Impacto
Puntuación base 3.x
6.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



