What is CVE-2026-68563?
A flaw in ansible-collection-redhat-leapp causes a PostgreSQL data backup archive to be created with insecure permissions when a remediation task runs with elevated privileges and the `leapp_old_postgresql_data` option is selected. This allows a local non-root user on the managed node to access the archive. Affected users should restrict the use of this option or update the collection.
Azərbaycanca: ansible-collection-redhat-leapp kolleksiyasında düzəliş tapşırığı yüksək imtiyazlarla icra edildikdə və `leapp_old_postgresql_data` seçimi aktiv olduqda PostgreSQL ehtiyat nüsxə arxivi təhlükəli icazələrlə yaradılır. Bu, idarə olunan node-da yerli qeyri-root istifadəçiyə həmin arxivə giriş imkanı verir. Təsirə məruz qalan sistemlərdə bu seçimin istifadəsini məhdudlaşdırmaq və ya kolleksiyanı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-732
FAQ1
Under what conditions does the CVE-2026-68563 vulnerability occur in ansible-collection-redhat-leapp?
This flaw occurs when a remediation task runs with elevated privileges and the `leapp_old_postgresql_data` option is selected, causing the PostgreSQL backup archive to be created with insecure permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.