
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19391 is a cleartext storage vulnerability in Red Hat's insights-core component where the password redaction layer fails to mask credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker CIB fence device credentials to be transmitted in cleartext within archives uploaded to console.redhat.com. The flaw was reported by Arpit Jain and published on August 8, 2026, with NVD publication on August 11, 2026. Affected products include insights-core, Red Hat pen-drive scanner (RHEL9), and Red Hat Certification Cloud images (RHEL9/10); the default insights-client configuration is affected with no non-default settings required. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Github Advisory).
The root cause is CWE-312 (Cleartext Storage of Sensitive Information): the redaction logic in insights/cleaner/password.py only scrubs configuration keys matching the literal string 'password', leaving non-standard credential keys unmasked. Specifically, SSSD's ldap_default_authtok key and Pacemaker CIB fence device credentials stored as XML attributes (name="passwd" value="...") bypass the cleaner entirely because the sssd_config, sssd_conf_d, and cib_xml specs are not declared filterable. As a result, full file contents — including LDAP bind passwords and cluster fence device credentials (IPMI, iLO, DRAC, vCenter) — are included unmodified in archives uploaded to console.redhat.com. Exploitation requires low privileges (an authenticated user with access to uploaded archives) and no user interaction (Red Hat CVE, Red Hat Bugzilla).
Successful exploitation allows any party with access to the uploaded Insights archives on console.redhat.com to read cleartext LDAP bind passwords and Pacemaker cluster fence device credentials (IPMI, iLO, DRAC, vCenter). The confidentiality impact is rated High, with no integrity or availability impact. Exposed LDAP credentials could enable unauthorized directory access and lateral movement within enterprise environments, while compromised fence device credentials could allow an attacker to disrupt or manipulate high-availability cluster operations (Red Hat CVE, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for low-privilege access to the uploaded archives. The EPSS score is approximately 0.151%, indicating a low near-term exploitation probability. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE, Github Advisory).
console.redhat.com or to the archive storage where Insights data is uploaded from affected systems running the default insights-client configuration.sssd_config, sssd_conf_d, or cib_xml specs.ldap_default_authtok key to retrieve the LDAP bind password in plaintext. For Pacemaker, inspect the CIB XML for fence device stanzas containing name="passwd" or name="password" attributes with cleartext values.ldap_default_authtok values in Insights archive tarballs (e.g., /var/lib/insights/ or uploaded archive contents); Pacemaker CIB XML files within archives containing plaintext passwd or password XML attributes for fence devices./var/log/insights-client/insights-client.log) showing successful archive uploads without redaction warnings for sssd_config, sssd_conf_d, or cib_xml specs.Red Hat has confirmed a patch is available for insights-core. As an immediate workaround, administrators should exclude the affected file specs by adding sssd_config, sssd_conf_d, and cib_xml to /etc/insights-client/file-redaction.yaml, or add keyword/pattern redaction rules covering ldap_default_authtok and the passwd/password XML attribute forms used by Pacemaker fence devices. Upgrading to a patched version of insights-core is the recommended long-term remediation. Organizations should also rotate any LDAP bind passwords and fence device credentials that may have been exposed in previously uploaded archives (Red Hat CVE, Red Hat Bugzilla).
Red Hat classified this as a Moderate severity flaw and credited researcher Arpit Jain (GitHub: arpitjain099) with the discovery. The Bugzilla report notes involvement of 25 CC'd users from Red Hat's product security and engineering teams, reflecting internal prioritization. No significant broader media coverage or notable public researcher commentary beyond the official Red Hat advisory has been identified at this time (Red Hat CVE, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."