CVE-2026-19550
EUVD-2026-5697711.08.2026, 21:17
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
| freeipa | freeipa | 𝑥 < 4.13.3 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| ipa-client |
| ||
| ipa-client-common |
| ||
| ipa-client-encrypted-dns |
| ||
| ipa-client-epn |
| ||
| ipa-client-samba |
| ||
| ipa-common |
| ||
| ipa-selinux |
| ||
| ipa-selinux-luna |
| ||
| ipa-selinux-nfast |
| ||
| ipa-server |
| ||
| ipa-server-common |
| ||
| ipa-server-dns |
| ||
| ipa-server-encrypted-dns |
| ||
| ipa-server-trust-ad |
| ||
| python3-ipaclient |
| ||
| python3-ipalib |
| ||
| python3-ipaserver |
| ||
| python3-ipatests |
|
Vulnerability Media Exposure