SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80158

MEDIUM · CVSS 5.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ipa_getkeytab module in the community.general Ansible collection is vulnerable due to the bind_pw parameter not being properly secured, leading to the LDAP simple-bind password being logged in cleartext in system journals and displayed in job outputs. This exposure allows local users to access sensitive credentials, potentially compromising accounts and objects associated with the bind password. Organizations using this Ansible module, especially those managing sensitive directory services, should prioritize addressing this vulnerability to mitigate the risk of credential theft.

CVE
CVE-2026-80158
Severity
MEDIUM
CVSS
5.5
EPSS
0.10%

Original NVD Description

A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host's system journal/syslog (the module's "Invoked with" record), is included in the module's return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw <value>), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.