YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services. | |
| Title | YugabyteDB Anywhere Exposes LDAP Credentials in Cleartext in Web UI | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Yugabyte
Published:
Updated: 2026-02-05T11:38:28.291Z
Reserved: 2026-02-05T11:27:51.783Z
Link: CVE-2026-1966
No data.
Status : Received
Published: 2026-02-05T12:16:01.467
Modified: 2026-02-05T12:16:01.467
Link: CVE-2026-1966
No data.
OpenCVE Enrichment
No data.