CVE-2026-19843
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Summary
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Directory Server 13.0 EUS for RHEL 10 | 0:3.0.6-4.el10dsrv < * | unaffected |
| Red Hat | Red Hat Directory Server 13.2 for RHEL 10 | 0:3.2.0-7.el10dsrv < * | unaffected |
Weaknesses
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Workarounds
Restrict Cockpit 389 Console access to trusted administrators, and restrict delegated LDAP add/rename privileges to trusted accounts, until a fix is available. This issue only affects Red Hat Directory Server deployments that include the Cockpit console; plain RHEL 389-ds-base is not affected.
References
- https://access.redhat.com/errata/RHSA-2026:64768
- https://access.redhat.com/errata/RHSA-2026:64769
- https://access.redhat.com/security/cve/CVE-2026-19843
- https://bugzilla.redhat.com/show_bug.cgi?id=2515965
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.