CVE-2026-19391
Insights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archives
Record summary
CVE-2026-19391 has a selected CVSS score of 6.5 (medium).
Description
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
11| Product | Source | Version range | Status |
|---|---|---|---|
Pen Drive Powered by Red Hat LightspeedBrowse Red Hat / Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Default status: affected | CVE List | Version data not supplied | |
Red Hat Certification Program for Red Hat Enterprise Linux 9Browse Red Hat / Red Hat Certification Program for Red Hat Enterprise Linux 9rhcertification/redhat-certification-cloud-10Default status: affected | CVE List | Version data not supplied | |
Red Hat Certification Program for Red Hat Enterprise Linux 9Browse Red Hat / Red Hat Certification Program for Red Hat Enterprise Linux 9rhcertification/redhat-certification-cloud-9Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |