Back to search
CVE-2026-1966
Published: Feb 5, 2026
Modified: Feb 5, 2026
PUBLISHED
Description
YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.
| Vendor | Product | Versions |
|---|---|---|
YugabyteDB Inc | YugabyteDB Anywhere | affected 2025.1.0.0 - < 2025.1.1.0affected 2024.2.0.0 - < 2024.2.6.0unaffected 2025.2.0.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now