AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19391

MEDIUM · CVSS 6.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability exists in the insights-core component, where the password redaction mechanism inadequately identifies credentials not explicitly labeled as 'password'. This oversight permits sensitive SSSD LDAP bind passwords and Pacemaker fence device credentials to be exposed in cleartext within archives sent to console.redhat.com. Organizations utilizing insights-core should prioritize addressing this flaw to mitigate the risk of credential leakage.

CVE
CVE-2026-19391
Severity
MEDIUM
CVSS
6.5
EPSS
0.15%

Original NVD Description

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.