Data Exposure Vulnerability in Canto SaaS API by Canto Technology
CVE-2026-55375
5.3MEDIUM
What is CVE-2026-55375?
The Canto SaaS API prior to version 3.0.0 exposes sensitive credential information, including app_id, app_secret, refresh_token, and code, in the URL query string of token POST requests. This implementation flaw permits inclusion of credentials in various logs, such as access logs and proxies, making them visible in plaintext. Additionally, if a token request fails, the Guzzle request URI that contains the sensitive data can be recorded in application and error logs. This vulnerability could allow unauthorized access to Canto credentials if an attacker has access to affected telemetry data, enabling them to request access tokens for the tenant. Version 3.0.0 addresses this security issue effectively.
Affected Version(s)
canto-saas-api < 3.0.0
