Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19843— 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor

Quick assessment

Affected
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

389-ds-base 中发现一个缺陷。 Cockpit 389 控制台的 LDAP 编辑器在构造 命令时,将 LDAP 条目的可分辨名称(DN)直接嵌入到 Shell 命令字符串中,且未进行适当的转义。 拥有目录条目创建或重命名委托权限的 LDAP 用户可以构造一个包含 Shell 元字符(metacharacters)的恶意 DN。当 Cockpit 管理员随后在 389 控制台中查看该条目时,嵌入的 Shell 命令将在目录服务器主机上以 root 权限执行,从而导致命令执行漏洞。

CVSS 8.4 · High

Affected Version Matrix 11

VendorProduct Version RangeStatus
Red Hat Red Hat Directory Server 11 any affected
any affected
Red Hat Red Hat Directory Server 12 any affected
any affected
Red Hat Red Hat Directory Server 13 any affected
Red Hat Red Hat Enterprise Linux 10 any affected
Red Hat Red Hat Enterprise Linux 6 any unknown
Red Hat Red Hat Enterprise Linux 7 any unaffected
Red Hat Red Hat Enterprise Linux 8 any affected
any unaffected
Red Hat Red Hat Enterprise Linux 9 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19843

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8 8080020260903102346.f969626e ~ * cpe:/a:redhat:directory_server_e4s:11.7::el8
Red Hat Red Hat Directory Server 11.9 for RHEL 8 8100020260904171440.37ed7c03 ~ * cpe:/a:redhat:directory_server:11.9::el8
Red Hat Red Hat Directory Server 12.2 E4S for RHEL 9 9020020260903155914.1674d574 ~ * cpe:/a:redhat:directory_server_e4s:12.2::el9
Red Hat Red Hat Directory Server 12.4 E4S for RHEL 9 9040020260903102623.1674d574 ~ * cpe:/a:redhat:directory_server_e4s:12.4::el9
Red Hat Red Hat Directory Server 12.6 EUS for RHEL 9 9060020260903100230.1674d574 ~ * cpe:/a:redhat:directory_server_eus:12.6::el9
Red Hat Red Hat Directory Server 13.0 EUS for RHEL 10 0:3.0.6-4.el10dsrv ~ * cpe:/a:redhat:directory_server_e2s:13.0::el10
Red Hat Red Hat Directory Server 13.2 for RHEL 10 0:3.2.0-7.el10dsrv ~ * cpe:/a:redhat:directory_server:13.2::el10
Red Hat Red Hat Directory Server 11 - cpe:/a:redhat:directory_server:11
Red Hat Red Hat Directory Server 12 - cpe:/a:redhat:directory_server:12
Red Hat Red Hat Directory Server 12 - cpe:/a:redhat:directory_server:12
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-19843

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19843

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19843 (2)

Other References for CVE-2026-19843 (7)

Same Patch Batch · Red Hat · 2026-09-07 · 10 CVEs total

CVE-2026-18922 9.8 CRITICAL 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directo
CVE-2026-76578 9.8 CRITICAL Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials vi
CVE-2026-86404 8.8 HIGH Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-
CVE-2026-79678 8.1 HIGH Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environm
CVE-2026-18453 7.5 HIGH 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results an
CVE-2026-18355 7.5 HIGH 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound
CVE-2026-76560 7.5 HIGH 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empt
CVE-2026-86332 6.5 MEDIUM Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user
CVE-2026-86469 5.3 MEDIUM Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path

IV. Related Vulnerabilities

V. Comments for CVE-2026-19843

No comments yet


Leave a comment