CVE-2026-19391
Received Received - Intake

SSSD LDAP Bind Credential Exposure in insights-core

Vulnerability report for CVE-2026-19391, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Red Hat, Inc.

Description

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
red_hat insights-core *
red_hat insights-client *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19391 is a flaw in Red Hat's insights-core software where the password redaction layer fails to mask credentials not explicitly labeled with the string 'password'. This allows sensitive information like SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to appear in cleartext within archives uploaded to console.redhat.com by the insights-client tool.

Detection Guidance

Check insights-client archives for unredacted credentials in sssd_config, sssd_conf_d, or cib_xml files. Inspect logs for insights-client uploads to console.redhat.com. Look for cleartext ldap_default_authtok or fence device passwords in XML attributes like name="passwd".

Impact Analysis

This vulnerability exposes sensitive credentials such as LDAP bind passwords and cluster fence device credentials (IPMI, iLO, DRAC, vCenter) in uploaded archives. Anyone with access to these archives could view these credentials, potentially leading to unauthorized access to systems or data.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to the cleartext storage and exposure of sensitive credentials. GDPR requires protection of personal data, while HIPAA mandates safeguarding protected health information. Unauthorized access to credentials may result in data breaches, violating these regulations.

Mitigation Strategies

Exclude sssd_config, sssd_conf_d, and cib_xml files via file-redaction.yaml. Add custom redaction for ldap_default_authtok and fence password XML forms. Monitor insights-client uploads until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19391. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart