CVE-2026-19391
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'pass
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-312
Not enough EPSS history yet.
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-619285.5 MED—
———Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.6hCVE-2026-47702——
———TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or insider access) can extract all API tokens and impersonate any user without requiring a password or multi-factor authentication. Version 3.17.0 fixes the issue.8hCVE-2026-21080—1.2%
——0Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.1dCVE-2026-203128.8 HIG8.5%
——3As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.5dCVE-2026-559978.8 HIG0.2%
——0Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.6dCVE-2026-157219.8 CRI14.0%
——4Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.7d