CVE-2026-68563: Incorrect Permission Assignment for Critical Resource in Red Hat Red Hat Enterprise Linux 10
CVE-2026-68563 is a medium severity vulnerability in the ansible-collection-redhat-leapp component used with Red Hat Enterprise Linux 10. When a remediation task is run with elevated privileges and the leapp_old_postgresql_data option is selected, a PostgreSQL data backup archive is created with insecure, overly permissive file permissions. This allows local non-root users on the managed node to read sensitive archived PostgreSQL data, resulting in information disclosure.
AI Analysis
Technical Summary
This vulnerability arises from incorrect permission assignment for a critical resource in ansible-collection-redhat-leapp. Specifically, when a remediation task that backs up old PostgreSQL data is executed with elevated privileges and the leapp_old_postgresql_data option is enabled, the resulting backup archive in /var/backups is created with world-readable permissions. This misconfiguration permits local non-root users on the managed node to access sensitive PostgreSQL data that should be protected. Exploitation requires local access and the presence of the PostgreSQL data directory at /var/lib/pgsql/data during the remediation task execution. The vulnerability is classified under CWE-732 (Incorrect Permission Assignment for Critical Resource) and has a CVSS v3.1 base score of 5.5 (medium severity) with a high confidentiality impact but no integrity or availability impact.
Potential Impact
The vulnerability allows local non-root users on affected systems to read sensitive PostgreSQL backup data that should be protected. This leads to information disclosure of potentially sensitive database contents. There is no impact on data integrity or availability. Exploitation requires local access and the execution of the specific remediation task with the leapp_old_postgresql_data option enabled.
Mitigation Recommendations
No official patch or fix is currently confirmed. To mitigate this issue, administrators should ensure that the directory used for PostgreSQL backups (e.g., /var/backups/leapp) is owned by root with restrictive permissions set to 0700, and that the backup archive files themselves have permissions set to 0600. This prevents unauthorized local users from reading the backup data. If the remediation task must be used without modification, local user access on affected systems should be restricted, and any generated backup archives should be immediately removed or have their permissions corrected after creation. These steps reduce the risk of unauthorized data disclosure.
CVE-2026-68563: Incorrect Permission Assignment for Critical Resource in Red Hat Red Hat Enterprise Linux 10
Description
CVE-2026-68563 is a medium severity vulnerability in the ansible-collection-redhat-leapp component used with Red Hat Enterprise Linux 10. When a remediation task is run with elevated privileges and the leapp_old_postgresql_data option is selected, a PostgreSQL data backup archive is created with insecure, overly permissive file permissions. This allows local non-root users on the managed node to read sensitive archived PostgreSQL data, resulting in information disclosure.
CVSS v3.1
Score 5.5medium
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 9
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from incorrect permission assignment for a critical resource in ansible-collection-redhat-leapp. Specifically, when a remediation task that backs up old PostgreSQL data is executed with elevated privileges and the leapp_old_postgresql_data option is enabled, the resulting backup archive in /var/backups is created with world-readable permissions. This misconfiguration permits local non-root users on the managed node to access sensitive PostgreSQL data that should be protected. Exploitation requires local access and the presence of the PostgreSQL data directory at /var/lib/pgsql/data during the remediation task execution. The vulnerability is classified under CWE-732 (Incorrect Permission Assignment for Critical Resource) and has a CVSS v3.1 base score of 5.5 (medium severity) with a high confidentiality impact but no integrity or availability impact.
Potential Impact
The vulnerability allows local non-root users on affected systems to read sensitive PostgreSQL backup data that should be protected. This leads to information disclosure of potentially sensitive database contents. There is no impact on data integrity or availability. Exploitation requires local access and the execution of the specific remediation task with the leapp_old_postgresql_data option enabled.
Mitigation Recommendations
No official patch or fix is currently confirmed. To mitigate this issue, administrators should ensure that the directory used for PostgreSQL backups (e.g., /var/backups/leapp) is owned by root with restrictive permissions set to 0700, and that the backup archive files themselves have permissions set to 0600. This prevents unauthorized local users from reading the backup data. If the remediation task must be used without modification, local user access on affected systems should be restricted, and any generated backup archives should be immediately removed or have their permissions corrected after creation. These steps reduce the risk of unauthorized data disclosure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-30T20:29:28.829Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-68563","vendor":"Red Hat"}]
Threat ID: 6a6bc4339c2644c7f8b99b00
Added to database: 07/30/2026, 21:37:55 UTC
Last enriched: 08/07/2026, 14:39:20 UTC
Last updated: 09/13/2026, 22:01:36 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.