CVE-2025-54876: Janssenproject Jans

Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.

The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.

Affected products

Published 2025-08-06. Last modified 2026-06-17.