{"id":"CVE-2026-58167","aliases":["GHSA-27c6-wp53-387x"],"title":"Nightingale exposes datasource credentials to low-privilege users","summary":"Nightingale exposes datasource credentials to low-privilege users","severity":"high","cvss":6.5,"cwe":["CWE-862"],"vendor":"ccfos","product":"github.com/ccfos/nightingale/v6","ecosystem":"go","affected":["github.com/ccfos/nightingale/v6 < 6.7.3-0.20260528033214-762819fbaa23"],"patched":["github.com/ccfos/nightingale/v6 6.7.3-0.20260528033214-762819fbaa23"],"published":"2026-06-30","updated":"2026-10-02","sourceUpdated":"2026-10-02T18:28:21Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-27c6-wp53-387x","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58167"},{"url":"https://github.com/ccfos/nightingale/issues/3173"},{"url":"https://github.com/ccfos/nightingale/pull/3175"},{"url":"https://github.com/ccfos/nightingale/commit/762819fbaa2350b73bce45bfaf6f8cf74b4abef8"},{"url":"https://github.com/ccfos/nightingale/releases/tag/v9.0.0-beta.2"},{"url":"https://www.vulncheck.com/advisories/nightingale-beta-2-datasource-credential-disclosure-to-low-privilege-users"},{"url":"https://github.com/advisories/GHSA-27c6-wp53-387x"}],"tags":["ghsa","go"],"epss":0.00415,"epssPercentile":0.33509,"ingestedAt":"2026-10-02T22:33:09.858Z","slug":"CVE-2026-58167","body":"## Overview\n\nNightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) user through POST /api/n9e/datasource/list. The route is registered without an admin authorization gate, unlike the sibling datasource mutation routes, and the open-source DatasourceFilter does not redact secret fields, so the secret-bearing settings, http, and auth objects are serialized in the response. The disclosed credentials enable access to the connected downstream systems.\n\n## Affected packages\n\n- `github.com/ccfos/nightingale/v6 < 6.7.3-0.20260528033214-762819fbaa23`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/ccfos/nightingale/v6 6.7.3-0.20260528033214-762819fbaa23`","depth":"twilight","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}