CVE-2026-19391
Linux Red Hat vulnerability analysis and mitigation

Overview

CVE-2026-19391 is a cleartext storage vulnerability in Red Hat's insights-core component where the password redaction layer fails to mask credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker CIB fence device credentials to be transmitted in cleartext within archives uploaded to console.redhat.com. The flaw was reported by Arpit Jain and published on August 8, 2026, with NVD publication on August 11, 2026. Affected products include insights-core, Red Hat pen-drive scanner (RHEL9), and Red Hat Certification Cloud images (RHEL9/10); the default insights-client configuration is affected with no non-default settings required. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Github Advisory).

Technical details

The root cause is CWE-312 (Cleartext Storage of Sensitive Information): the redaction logic in insights/cleaner/password.py only scrubs configuration keys matching the literal string 'password', leaving non-standard credential keys unmasked. Specifically, SSSD's ldap_default_authtok key and Pacemaker CIB fence device credentials stored as XML attributes (name="passwd" value="...") bypass the cleaner entirely because the sssd_config, sssd_conf_d, and cib_xml specs are not declared filterable. As a result, full file contents — including LDAP bind passwords and cluster fence device credentials (IPMI, iLO, DRAC, vCenter) — are included unmodified in archives uploaded to console.redhat.com. Exploitation requires low privileges (an authenticated user with access to uploaded archives) and no user interaction (Red Hat CVE, Red Hat Bugzilla).

Impact

Successful exploitation allows any party with access to the uploaded Insights archives on console.redhat.com to read cleartext LDAP bind passwords and Pacemaker cluster fence device credentials (IPMI, iLO, DRAC, vCenter). The confidentiality impact is rated High, with no integrity or availability impact. Exposed LDAP credentials could enable unauthorized directory access and lateral movement within enterprise environments, while compromised fence device credentials could allow an attacker to disrupt or manipulate high-availability cluster operations (Red Hat CVE, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for low-privilege access to the uploaded archives. The EPSS score is approximately 0.151%, indicating a low near-term exploitation probability. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE, Github Advisory).

Exploitation steps

  1. Gain access to uploaded archives: Obtain low-privileged access to console.redhat.com or to the archive storage where Insights data is uploaded from affected systems running the default insights-client configuration.
  2. Locate relevant archive files: Within the uploaded Insights archive (typically a compressed tarball), navigate to the collected configuration files — specifically those derived from sssd_config, sssd_conf_d, or cib_xml specs.
  3. Extract cleartext credentials: Open the SSSD configuration file and locate the ldap_default_authtok key to retrieve the LDAP bind password in plaintext. For Pacemaker, inspect the CIB XML for fence device stanzas containing name="passwd" or name="password" attributes with cleartext values.
  4. Leverage credentials: Use the extracted LDAP bind password to authenticate against the organization's LDAP/Active Directory server, or use fence device credentials (IPMI, iLO, DRAC, vCenter) to access out-of-band management interfaces for lateral movement or disruption (Red Hat Bugzilla, Red Hat CVE).

Indicators of compromise

  • File System: Presence of unredacted ldap_default_authtok values in Insights archive tarballs (e.g., /var/lib/insights/ or uploaded archive contents); Pacemaker CIB XML files within archives containing plaintext passwd or password XML attributes for fence devices.
  • Logs: Insights client upload logs (/var/log/insights-client/insights-client.log) showing successful archive uploads without redaction warnings for sssd_config, sssd_conf_d, or cib_xml specs.
  • Network: Unexpected authentication attempts against LDAP/AD servers or out-of-band management interfaces (IPMI, iLO, DRAC, vCenter) using credentials that match those stored in SSSD or Pacemaker configurations, originating from unfamiliar hosts (Red Hat Bugzilla).

Mitigation and workarounds

Red Hat has confirmed a patch is available for insights-core. As an immediate workaround, administrators should exclude the affected file specs by adding sssd_config, sssd_conf_d, and cib_xml to /etc/insights-client/file-redaction.yaml, or add keyword/pattern redaction rules covering ldap_default_authtok and the passwd/password XML attribute forms used by Pacemaker fence devices. Upgrading to a patched version of insights-core is the recommended long-term remediation. Organizations should also rotate any LDAP bind passwords and fence device credentials that may have been exposed in previously uploaded archives (Red Hat CVE, Red Hat Bugzilla).

Community reactions

Red Hat classified this as a Moderate severity flaw and credited researcher Arpit Jain (GitHub: arpitjain099) with the discovery. The Bugzilla report notes involvement of 25 CC'd users from Red Hat's product security and engineering teams, reflecting internal prioritization. No significant broader media coverage or notable public researcher commentary beyond the official Red Hat advisory has been identified at this time (Red Hat CVE, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Red Hat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management