Unknown · Foreman-Mcp-Server · CVE-2026-9073
**Name of the Vulnerable Software and Affected Versions**
foreman-mcp-server (affected versions not specified)
**Description**
Two distinct logging mechanisms in the software can expose sensitive session and authentication data. One mechanism logs session identifiers, which function as authentication credentials, at an informational level. A second mechanism, active when debug logging is enabled, fails to completely sanitize HTTP request headers, resulting in the cleartext logging of API keys and authorization tokens. This leads to a confidentiality breach where sensitive data is stored in plain text within container logs, which increases risk if logs are sent to a centralized platform.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.