Junglewise Threat Intelligence

CVE-2026-19391: Red Hat insights-core incomplete credential redaction

CVE-2026-19391 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Vendors: Red Hat.

Executive brief

insights-core is Red Hat's system analysis and reporting tool that collects system configuration data for analysis and compliance purposes. A flaw in its credential redaction mechanism fails to mask SSSD LDAP bind passwords and Pacemaker fence device credentials before uploading archives to Red Hat's cloud console, potentially exposing sensitive authentication credentials to anyone with access to these uploaded files.

Technical details

The vulnerability is a cleartext information disclosure (CWE-312) in the password redaction layer of insights-core. The redaction logic only recognizes credentials explicitly keyed under the literal string 'password', causing it to miss SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials that use different key names. An attacker with access to uploaded archives on console.redhat.com can read these sensitive credentials. Affected systems using the default insights-client configuration automatically upload impacted data. Mitigation involves excluding specific configuration files or adding custom keyword/pattern redaction rules until a patched version is deployed.

Affected products

  • Red Hat insights-core

Timeline

  • 2026-08-11: disclosed
  • other: Not observed exploited in the wild at time of disclosure

References