CVE-2026-19550

EUVD-2026-56977
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 17.85%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
freeipafreeipa
𝑥
< 4.13.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freeipa
bookworm
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeipa
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ipa-client
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-encrypted-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-epn
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-samba
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux-luna
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux-nfast
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-encrypted-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-trust-ad
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipaclient
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipalib
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipaserver
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipatests
RHEL 9
0:4.13.4-1.el9_8
fixed