---
id: CVE-2026-58167
aliases:
  - GHSA-27c6-wp53-387x
title: Nightingale exposes datasource credentials to low-privilege users
summary: Nightingale exposes datasource credentials to low-privilege users
severity: high
cvss: 6.5
cwe:
  - CWE-862
vendor: ccfos
product: github.com/ccfos/nightingale/v6
ecosystem: go
affected:
  - github.com/ccfos/nightingale/v6 < 6.7.3-0.20260528033214-762819fbaa23
patched:
  - github.com/ccfos/nightingale/v6 6.7.3-0.20260528033214-762819fbaa23
published: '2026-06-30'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:28:21Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-27c6-wp53-387x'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58167'
  - url: 'https://github.com/ccfos/nightingale/issues/3173'
  - url: 'https://github.com/ccfos/nightingale/pull/3175'
  - url: >-
      https://github.com/ccfos/nightingale/commit/762819fbaa2350b73bce45bfaf6f8cf74b4abef8
  - url: 'https://github.com/ccfos/nightingale/releases/tag/v9.0.0-beta.2'
  - url: >-
      https://www.vulncheck.com/advisories/nightingale-beta-2-datasource-credential-disclosure-to-low-privilege-users
  - url: 'https://github.com/advisories/GHSA-27c6-wp53-387x'
tags:
  - ghsa
  - go
epss: 0.00415
epssPercentile: 0.33509
ingestedAt: '2026-10-02T22:33:09.858Z'
---

## Overview

Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) user through POST /api/n9e/datasource/list. The route is registered without an admin authorization gate, unlike the sibling datasource mutation routes, and the open-source DatasourceFilter does not redact secret fields, so the secret-bearing settings, http, and auth objects are serialized in the response. The disclosed credentials enable access to the connected downstream systems.

## Affected packages

- `github.com/ccfos/nightingale/v6 < 6.7.3-0.20260528033214-762819fbaa23`

## Remediation

Upgrade to a patched release:

- `github.com/ccfos/nightingale/v6 6.7.3-0.20260528033214-762819fbaa23`
