
PEACH
Un cadre d’isolation des locataires
CVE-2026-19391 is a cleartext storage vulnerability in Red Hat's insights-core component where the password redaction layer fails to mask credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker CIB fence device credentials to be transmitted in cleartext within archives uploaded to console.redhat.com. The flaw was reported by Arpit Jain and published on August 8, 2026, with patch details added on August 10–11, 2026. Affected products include insights-core, pen-drive-scanner-rhel9, rhcertification/redhat-certification-cloud-9/10, and rhel10/rhel-bootc images. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, GitHub Advisory).
The root cause is classified as CWE-312 (Cleartext Storage of Sensitive Information). The redaction logic in insights/cleaner/password.py only scrubs configuration keys matching the literal string 'password', leaving alternative credential key names unhandled. Specifically, SSSD's ldap_default_authtok key and Pacemaker CIB fence device credentials stored as XML attributes (name="passwd" value="...") bypass redaction entirely because the sssd_config, sssd_conf_d, and cib_xml specs are not declared as filterable. As a result, the full file contents pass through the cleaner unmodified, and credentials for IPMI, iLO, DRAC, and vCenter fence devices are included in cleartext in uploaded archives. No non-default configuration is required to trigger the exposure — the default insights-client setup is affected (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation allows any party with access to the uploaded archives on console.redhat.com to read LDAP bind passwords and cluster fence device credentials (IPMI, iLO, DRAC, vCenter) in cleartext. The confidentiality impact is rated High, with no integrity or availability impact. Exposure of LDAP bind credentials could enable unauthorized directory access and lateral movement within enterprise environments, while compromised fence device credentials could allow an attacker to manipulate high-availability cluster operations (Red Hat CVE, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported. The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.0015 (0.15%), reflecting a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low privileges (authenticated access to the uploaded archives on console.redhat.com) rather than direct system access (Red Hat CVE, GitHub Advisory).
console.redhat.com (e.g., a Red Hat Insights account with access to the target organization's uploaded data) identifies archives submitted by systems running insights-client.sssd_config/sssd_conf_d (e.g., /etc/sssd/sssd.conf) or cib_xml (Pacemaker CIB XML). These files are included unmodified due to the redaction bypass.ldap_default_authtok value from the SSSD configuration to obtain the LDAP bind password, or parse the Pacemaker CIB XML for fence device credential attributes (name="passwd" or name="password") to obtain IPMI/iLO/DRAC/vCenter passwords.sssd.conf or SSSD drop-in configuration files within Insights archive tarballs; Pacemaker CIB XML files (cib.xml) included in archives with plaintext passwd or password attribute values in fence device stanzas.insights-client upload logs showing successful archive submission without redaction warnings for sssd_config, sssd_conf_d, or cib_xml specs; absence of redaction entries for ldap_default_authtok in cleaner output.Red Hat recommends the following workarounds until a patched version of insights-core is available: exclude the affected specs by adding sssd_config, sssd_conf_d, and cib_xml to /etc/insights-client/file-redaction.yaml, or add keyword/pattern-based redaction rules covering ldap_default_authtok and the fence device passwd/password XML attribute forms. Organizations should also audit previously uploaded Insights archives for exposed credentials and rotate any LDAP bind passwords or fence device credentials that may have been included. Monitor the Red Hat CVE page and Bugzilla entry for the release of a patched insights-core package (Red Hat CVE, Red Hat Bugzilla).
Red Hat acknowledged the flaw as Moderate severity and credited researcher Arpit Jain (GitHub: arpitjain099) for responsible disclosure. The advisory notes that the default insights-client configuration is affected, which broadens the potential impact across standard RHEL deployments using Red Hat Insights. No significant broader media coverage or notable community commentary beyond the official Red Hat advisory and Bugzilla entry has been observed at this time (Red Hat CVE, Red Hat Bugzilla).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."