A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade freeipa-server | Sep 18, 2026 | Sep 11, 2026 |
| Redhat_linux | — | Upgrade python3-ipaclientUpgrade python3-ipalibUpgrade ipa-client-debuginfoUpgrade ipa-server-commonUpgrade ipa-selinuxUpgrade python3-ipatestsUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-server-dnsUpgrade ipa-client-sambaUpgrade ipa-clientUpgrade ipa-serverUpgrade ipa-client-epnUpgrade ipa-selinux-nfastNo solution existsUpgrade ipa-selinux-lunaUpgrade ipa-server-debuginfoUpgrade ipa-server-trust-adUpgrade ipa-server-encrypted-dnsUpgrade ipa-debugsourceUpgrade python3-ipaserverUpgrade ipa-commonUpgrade ipa-debuginfoUpgrade ipa-client-commonUpgrade ipa-client-encrypted-dns | Sep 9, 2026 | Sep 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub