Password Redaction Vulnerability in Insights-Core by Red Hat
CVE-2026-19391
6.5MEDIUM
What is CVE-2026-19391?
A security flaw exists in the insights-core component of Red Hat, where the password redaction mechanism fails to properly redact sensitive information. This flaw allows credentials such as SSSD LDAP bind passwords and Pacemaker fence device credentials to be exposed in cleartext within archives submitted to console.redhat.com. As a result, this vulnerability presents a risk of unauthorized access to sensitive systems, as these credentials may be included in logs or reports without adequate protection.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Arpit Jain (GitHub handle: arpitjain099) for reporting this issue.