Executive brief
Nightingale, an open-source monitoring and operations platform, contains a security flaw that allows users with standard, low-level access to view sensitive administrative credentials. This includes plaintext passwords for databases like MySQL and PostgreSQL, as well as security tokens and private keys used to connect to other corporate systems. An attacker with a basic account could use this information to gain unauthorized access to the organization's broader data infrastructure.
Technical details
A missing authorization check (CWE-862) in Nightingale (n9e) allows authenticated users with the 'Standard' role to access sensitive datasource configurations. While administrative mutation routes are protected, the 'POST /api/n9e/datasource/list' endpoint lacks an admin authorization gate. Furthermore, the 'DatasourceFilter' component fails to redact secret fields during JSON serialization. Consequently, the response includes plaintext database passwords (MySQL, Postgres, ClickHouse), HTTP bearer tokens, basic-auth credentials, and mTLS client private keys. This allows a low-privileged attacker to exfiltrate credentials for all downstream systems connected to the platform. The issue is resolved in version 9.0.0-beta.2 by implementing a 'RedactSecrets' method for non-admin requests.
Affected products
- ccfos Nightingale (n9e) before 9.0.0-beta.2
Timeline
- 2026-05-27: disclosed: Vulnerability reported via GitHub issue
- 2026-05-28: patched: Fix committed to main branch
- 2026-05-29: advisory: Version 9.0.0-beta.2 released
- 2026-06-30: advisory: CVE published and NVD record created
References
- https://github.com/ccfos/nightingale/commit/762819fbaa2350b73bce45bfaf6f8cf74b4abef8
- https://github.com/ccfos/nightingale/issues/3173
- https://github.com/ccfos/nightingale/pull/3175
- https://github.com/ccfos/nightingale/releases/tag/v9.0.0-beta.2
- https://www.vulncheck.com/advisories/nightingale-beta-2-datasource-credential-disclosure-to-low-privilege-users