CVE-2026-80158
Last modified
CVE-2026-80158 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host's system journal/syslog (the module's "Invoked with" record), is included in the module's return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw <value>), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Ceph Storage 5 | All versions |
| Red Hat | Red Hat Ceph Storage 9 | All versions |
| Red Hat | Red Hat OpenStack Platform 17.1 | All versions |
| Red Hat | Red Hat OpenStack Platform 18.0 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-80158?
How severe is CVE-2026-80158?
How do I fix CVE-2026-80158?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8012Inappropriate implementation in MHTML in Google Chrome prior…5.4
- CVE-2026-8013Insufficient validation of untrusted input in FedCM in Googl…4.3
- CVE-2026-80138ClipBucket V5's web installer fails to properly validate or …9.8
- CVE-2026-8014Inappropriate implementation in Preload in Google Chrome pri…4.3
- CVE-2026-8015Inappropriate implementation in Media in Google Chrome prior…5.4
- CVE-2026-80153Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-8016Use after free in WebRTC in Google Chrome prior to 148.0.777…8.8
- CVE-2026-8017Side-channel information leakage in Media in Google Chrome p…3.1
- CVE-2026-80179A flaw was found in jwcrypto. A remote attacker can send a s…5.9
- CVE-2026-8018Insufficient policy enforcement in DevTools in Google Chrome…8.1
- CVE-2026-80182In OpenStack Keystone before 29.0.3, tokens obtained via OAu…7.6
- CVE-2026-80183In OpenStack Keystone before 29.0.3, any authenticated user …7.1
Are you affected by CVE-2026-80158?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
