An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.
https://github.com/Kettn/Vulnerability_Publications
https://github.com/Kettn/Vulnerability_Publications/tree/main/CVE-2026-39007