YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services. | |
| Title | YugabyteDB Anywhere Exposes LDAP Credentials in Cleartext in Web UI | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Yugabyte
Published:
Updated: 2026-02-05T14:18:33.527Z
Reserved: 2026-02-05T11:27:51.783Z
Link: CVE-2026-1966
Updated: 2026-02-05T14:18:29.868Z
Status : Awaiting Analysis
Published: 2026-02-05T12:16:01.467
Modified: 2026-02-05T14:57:20.563
Link: CVE-2026-1966
No data.