SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-68563

MEDIUM · CVSS 5.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A vulnerability exists in ansible-collection-redhat-leapp that affects the handling of PostgreSQL data backups when executed with elevated privileges. The flaw results in the creation of a backup archive with insecure permissions, allowing local non-root users on the managed node to access sensitive data, which can lead to information disclosure. Organizations utilizing this Ansible collection, particularly those managing PostgreSQL databases, should prioritize remediation efforts to mitigate potential data exposure risks.

CVE
CVE-2026-68563
Severity
MEDIUM
CVSS
5.5
EPSS
0.10%

Original NVD Description

A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive archived PostgreSQL data, leading to information disclosure.