CVE-2026-27640Disclosure(oocx / tfplan2md)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch oocx tfplan2md systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This caused reports to render values that should have been masked as "(sensitive)" instead. This issue is fixed in v1.26.1. No known workarounds are available.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-212

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tfplan2md

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
tfplan2md

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-25: 2Mentions · 2026-03-02: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-02: 102-2503-02
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-252
Disclosure1Patch1
2026-03-021
General1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27640 (CVSS:8.5, HIGH) is Analyzed. tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1...https://nvd.nist.gov/vuln/detail/CVE-2026-27640 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post briefly references CVE‑2026‑27640, noting its CVSS score and severity, but offers no further details on exploitation, patches, or PoC.

    0000030
    173 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27640 tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several dist… https://www.cve.org/CVERecord?id=CVE-2026-27640

    Post summary

    The CVE refers to a bug in tfplan2md that was fixed in version 1.26.1, with no details on exploitation or PoC.

    0000094
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27640 Sensitive Data Exposure in tfplan2md Before Version 1.26.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27640

    Post summary

    A new vulnerability, CVE-2026-27640, is disclosed as a sensitive data exposure issue in tfplan2md versions prior to 1.26.1, with no PoC, exploit, or patch details provided.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appoocxtfplan2md---

Explore more