
CVE-2026-1966 YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could… https://www.cve.org/CVERecord?id=CVE-2026-1966
Post summary
CVE-2026-1966 exposes cleartext LDAP bind passwords in YugabyteDB Anywhere’s web UI to authenticated users, highlighting a disclosure of a credential‑leak vulnerability.

