YugabyteDB Anywhere Exposes LDAP Credentials in Cleartext in Web UI
Published Feb 5, 2026
2.4
LOWCVSS 4.0
EPSS 0.18%
Description
YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.
Affected products
-
- Version 2024.2.0.0StatusaffectedConstraints<2024.2.6.0
- Version 2025.1.0.0StatusaffectedConstraints<2025.1.1.0
- Version 2025.2.0.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| YugabyteDB Inc | YugabyteDB Anywhere | unaffected |
|
No data.
No data.
Red Hat JBoss Enterprise Application Platform 8
yugabytedb
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
yugabytedb
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8 | yugabytedb | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | yugabytedb | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
LOW impact: Authenticated users with access to the configuration view of YugabyteDB Anywhere can obtain LDAP bind passwords displayed in cleartext within the web UI. This information disclosure could lead to unauthorized access to external directory services.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-1966 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2437046 Issue Tracking
- https://docs.yugabyte.com/stable/secure/vulnerability-disclosure-policy/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5553 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-1966
- https://www.cve.org/CVERecord?id=CVE-2026-1966
Change history (0)
No recorded changes yet.