CVE-2026-19391
Linux Red Hat Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-19391 is a cleartext storage vulnerability in Red Hat's insights-core component where the password redaction layer fails to mask credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker CIB fence device credentials to be transmitted in cleartext within archives uploaded to console.redhat.com. The flaw was reported by Arpit Jain and published on August 8, 2026, with patch details added on August 10–11, 2026. Affected products include insights-core, pen-drive-scanner-rhel9, rhcertification/redhat-certification-cloud-9/10, and rhel10/rhel-bootc images. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, GitHub Advisory).

Détails techniques

The root cause is classified as CWE-312 (Cleartext Storage of Sensitive Information). The redaction logic in insights/cleaner/password.py only scrubs configuration keys matching the literal string 'password', leaving alternative credential key names unhandled. Specifically, SSSD's ldap_default_authtok key and Pacemaker CIB fence device credentials stored as XML attributes (name="passwd" value="...") bypass redaction entirely because the sssd_config, sssd_conf_d, and cib_xml specs are not declared as filterable. As a result, the full file contents pass through the cleaner unmodified, and credentials for IPMI, iLO, DRAC, and vCenter fence devices are included in cleartext in uploaded archives. No non-default configuration is required to trigger the exposure — the default insights-client setup is affected (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation allows any party with access to the uploaded archives on console.redhat.com to read LDAP bind passwords and cluster fence device credentials (IPMI, iLO, DRAC, vCenter) in cleartext. The confidentiality impact is rated High, with no integrity or availability impact. Exposure of LDAP bind credentials could enable unauthorized directory access and lateral movement within enterprise environments, while compromised fence device credentials could allow an attacker to manipulate high-availability cluster operations (Red Hat CVE, Red Hat Bugzilla).

Exploitabilité

No public proof-of-concept exploit code or in-the-wild exploitation has been reported. The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.0015 (0.15%), reflecting a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low privileges (authenticated access to the uploaded archives on console.redhat.com) rather than direct system access (Red Hat CVE, GitHub Advisory).

Étapes d’exploitation

  1. Gain access to uploaded archives: An attacker with low-privileged access to console.redhat.com (e.g., a Red Hat Insights account with access to the target organization's uploaded data) identifies archives submitted by systems running insights-client.
  2. Download the archive: Retrieve the Insights archive (typically a compressed tarball) uploaded by the target system.
  3. Locate unredacted credential files: Within the archive, navigate to files corresponding to sssd_config/sssd_conf_d (e.g., /etc/sssd/sssd.conf) or cib_xml (Pacemaker CIB XML). These files are included unmodified due to the redaction bypass.
  4. Extract cleartext credentials: Read the ldap_default_authtok value from the SSSD configuration to obtain the LDAP bind password, or parse the Pacemaker CIB XML for fence device credential attributes (name="passwd" or name="password") to obtain IPMI/iLO/DRAC/vCenter passwords.
  5. Leverage credentials: Use the extracted LDAP bind password to authenticate against the organization's LDAP/Active Directory infrastructure, or use fence device credentials to access out-of-band management interfaces for lateral movement or disruption (Red Hat Bugzilla, Red Hat CVE).

Indicateurs de compromis

  • File System: Presence of unredacted sssd.conf or SSSD drop-in configuration files within Insights archive tarballs; Pacemaker CIB XML files (cib.xml) included in archives with plaintext passwd or password attribute values in fence device stanzas.
  • Logs: insights-client upload logs showing successful archive submission without redaction warnings for sssd_config, sssd_conf_d, or cib_xml specs; absence of redaction entries for ldap_default_authtok in cleaner output.
  • Network: Unexpected authentication attempts against LDAP/Active Directory servers or out-of-band management interfaces (IPMI, iLO, DRAC, vCenter) using credentials that match those stored in SSSD or Pacemaker configurations, originating from unfamiliar sources (Red Hat Bugzilla).

Atténuation et solutions de contournement

Red Hat recommends the following workarounds until a patched version of insights-core is available: exclude the affected specs by adding sssd_config, sssd_conf_d, and cib_xml to /etc/insights-client/file-redaction.yaml, or add keyword/pattern-based redaction rules covering ldap_default_authtok and the fence device passwd/password XML attribute forms. Organizations should also audit previously uploaded Insights archives for exposed credentials and rotate any LDAP bind passwords or fence device credentials that may have been included. Monitor the Red Hat CVE page and Bugzilla entry for the release of a patched insights-core package (Red Hat CVE, Red Hat Bugzilla).

Réactions de la communauté

Red Hat acknowledged the flaw as Moderate severity and credited researcher Arpit Jain (GitHub: arpitjain099) for responsible disclosure. The advisory notes that the default insights-client configuration is affected, which broadens the potential impact across standard RHEL deployments using Red Hat Insights. No significant broader media coverage or notable community commentary beyond the official Red Hat advisory and Bugzilla entry has been observed at this time (Red Hat CVE, Red Hat Bugzilla).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Linux Red Hat Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-72693HIGH7.8
  • Linux Red Hat logoLinux Red Hat
  • kbd-legacy
NonNonAug 11, 2026
CVE-2026-71217HIGH7.5
  • Linux Red Hat logoLinux Red Hat
  • iperf3
NonNonAug 11, 2026
CVE-2026-72694HIGH7.1
  • Linux Red Hat logoLinux Red Hat
  • mrtg
NonNonAug 11, 2026
CVE-2026-19391MEDIUM6.5
  • Linux Red Hat logoLinux Red Hat
  • insights-core-selinux
NonNonAug 11, 2026
CVE-2026-71218MEDIUM5.3
  • Linux Red Hat logoLinux Red Hat
  • iperf3
NonNonAug 11, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités