CVE-2026-1966: Yugabytedb Inc Yugabytedb Anywhere

Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

Affected products

  • Yugabytedb Inc Yugabytedb Anywhere: from 2025.1.0.0, before 2025.1.1.0 (fixed in 2025.1.1.0); from 2024.2.0.0, before 2024.2.6.0 (fixed in 2024.2.6.0)

Published 2026-02-05. Last modified 2026-06-17.