What is CVE-2026-19391?
A vulnerability in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This flaw leads to SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials being exposed in cleartext within uploaded archives. Affected users should immediately apply the necessary patches to prevent credential leakage.
Azərbaycanca: insights-core alətində şifrə gizlətmə qatının 'password' açar sözünü tanımaması nəticəsində yaranan boşluqdur. Bu qüsur, SSSD LDAP bağlanma şifrələri (ldap_default_authtok) və Pacemaker fence cihaz etimadnamələrinin arxivlərə açıq mətn şəklində daxil edilməsinə səbəb olur. Təsirə məruz qalan istifadəçilər, şifrələrin sızmasının qarşısını almaq üçün dərhal müvafiq yeniləmələri tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-522
FAQ2
What types of credentials are affected by CVE-2026-19391?
This vulnerability affects SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials.
How does CVE-2026-19391 lead to credential exposure?
The password redaction layer in insights-core fails to recognize credentials not keyed under the literal string 'password', causing those passwords to be included in cleartext within uploaded archives.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.