Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1966

15
FAUCET Score

CVE-2026-1966 describes a vulnerability in YugabyteDB Anywhere where LDAP bind passwords are displayed in cleartext within the web UI. This allows an authenticated user with configuration access to view sensitive LDAP credentials. The vulnerability has a low CVSS score of 2.4 due to requiring physical access, high attack complexity, and high privileges, but could lead to unauthorized access to external directory services. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
YugabyteDB IncYugabyteDB Anywhere
>= 2024.2.0.0, < 2024.2.6.0, >= 2025.1.0.0, < 2025.1.1.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

2.4LOW

CVSS:4.0/AV:P/AC:H/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
PHYSICAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
ACTIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 50th percentile among its peer group of 3 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: yugabytedb
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: yugabytedb

Vendor Advisories (1)

redhatCVE-2026-1966Low

YugabyteDB: YugabyteDB Anywhere: Information disclosure of LDAP bind passwords via web UI

Feb 5, 2026

References

docs.yugabyte.com / stable/secure/vulnerability-disclosure-policy