Ad

CVE-2026-1966

LOW CVSS 4.0: 2.4 EPSS 0.03%
Updated Feb 05, 2026
YugabyteDB
Parameter Value
CVSS 2.4 (LOW)
Type CWE-522 (Insufficiently Protected Credentials)
Vendor YugabyteDB
Public PoC No

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

Attack Parameters

Attack Vector
Physical
Requires physical access
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
High
Admin privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v4.0