VYPR

ansible-collection-redhat-leapp

by Red Hat

CVEs (2)

  • CVE-2026-68562MedJul 30, 2026
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own…

  • CVE-2026-68563MedJul 30, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on…