CVE-2026-27900Disclosure(terraform / linode_provider)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch terraform linode_provider systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by default. This issue is exposed when debug/provider logs are explicitly enabled (for example in local troubleshooting, CI/CD jobs, or centralized log collection). If enabled, sensitive values may be written to logs and then retained, shared, or exported beyond the original execution environment. An authenticated user with access to provider debug logs (through log aggregation systems, CI/CD pipelines, or debug output) would thus be able to extract these sensitive credentials. Versions 3.9.0 and later sanitize debug logs by logging only non-sensitive metadata such as labels, regions, and resource IDs while redacting credentials, tokens, keys, scripts, and other sensitive content. Some other mitigations and workarounds are available. Disable Terraform/provider debug logging or set it to `WARN` level or above, restrict access to existing and historical logs, purge/retention-trim logs that may contain sensitive values, and/or rotate potentially exposed secrets/credentials.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linode_provider

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-26); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
linode_provider

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-26: 2Mentions · 2026-03-06: 1Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-02-26: 2Technical Details · 2026-03-06: 102-2603-0603-12
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure2
2026-03-061
Disclosure1
2026-03-121
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-27900: Terraform Provider for Linode: Sensitive Information Exposure in Debug Logs https://www.openwall.com/lists/oss-security/2026/02/26/2 versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, object storage data, and NodeBalancer TLS keys

    Post summary

    The post announces CVE‑2026‑27900, describing sensitive data leakage via Terraform Linode provider debug logs and the affected versions, with an implied fix in v3.9.0.

    03052621
    4.4K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Terraform Provider for Linode, Information Exposure, #CVE-2026-27900 (Medium) https://dailycve.com/terraform-provider-for-linode-information-exposure-cve-2026-27900-medium/

    Post summary

    A medium‑severity information‑exposure vulnerability (CVE‑2026‑27900) was disclosed in the Terraform Provider for Linode, as noted on DailyCVE.

    0000032
    167 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27900: The Chatterbox Cloud: Leaking Root in Linode Terraform Provider A classic case of 'logging too much,' the Linode Terraform Provider (prior to v3.9.0) treated debug logs as a confessional booth, whispering root passwords, SSL keys, and ... https://cvereports.com/reports/CVE-2026-27900

    Post summary

    The Linode Terraform Provider (pre‑v3.9.0) improperly logs sensitive credentials, exposing root passwords and SSL keys, as detailed in CVE‑2026‑27900.

    0000040
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27900 The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debu… https://www.cve.org/CVERecord?id=CVE-2026-27900

    Post summary

    The CVE highlights a logging flaw in the Terraform Provider for Linode that could expose sensitive data; no PoC, exploit, or patch details are provided.

    00000121
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appterraformlinode_provider---

Explore more