CVE-2026-19391

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 07:17

Updated : 2026-08-14 19:07


NVD link : CVE-2026-19391

Mitre link : CVE-2026-19391

CVE.ORG link : CVE-2026-19391


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information