CVE-2026-1966 describes a vulnerability in YugabyteDB Anywhere where LDAP bind passwords are displayed in cleartext within the web UI. This allows an authenticated user with configuration access to view sensitive LDAP credentials. The vulnerability has a low CVSS score of 2.4 due to requiring physical access, high attack complexity, and high privileges, but could lead to unauthorized access to external directory services. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| YugabyteDB Inc | YugabyteDB Anywhere | >= 2024.2.0.0, < 2024.2.6.0, >= 2025.1.0.0, < 2025.1.1.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:H/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.