Information Disclosure in Vaadin Maven and Gradle Plugins by Vaadin
CVE-2026-7860

1.6LOW

Key Information:

Vendor

Vaadin

Status
Vendor
CVE Published:
19 May 2026

What is CVE-2026-7860?

An information disclosure vulnerability exists in the Vaadin Maven and Gradle plugins that can expose sensitive environment variables in clear text if a frontend build fails. This occurs when the build process exits with a non-zero status, revealing secrets, including credentials, within CI logs and archived artifacts. To mitigate this risk, users are advised to upgrade to the specified patched versions to secure their build environments.

Affected Version(s)

flow 23.0.0 <= 23.6.10

flow 24.0.0 <= 24.9.17

flow 24.10.0 <= 24.10.3

References

CVSS V4

Score:
1.6
Severity:
LOW
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.