389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.4epss 0.5%
from disclosure to weapon0 days
Published on NVDSep 7
1st PoCAug 24
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
Red Hat · Red Hat Directory Server 11Red Hat · Red Hat Directory Server 11.7 E4S for RHEL 8Red Hat · Red Hat Directory Server 11.9 for RHEL 8Red Hat · Red Hat Directory Server 12Red Hat · Red Hat Directory Server 12.2 E4S for RHEL 9Red Hat · Red Hat Directory Server 12.4 E4S for RHEL 9Red Hat · Red Hat Directory Server 12.6 EUS for RHEL 9Red Hat · Red Hat Directory Server 12.8 for RHEL 9Red Hat · Red Hat Directory Server 13.0 EUS for RHEL 10Red Hat · Red Hat Directory Server 13.2 for RHEL 10Red Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9public PoCs found — 1
githubgithub.com/gduma-phData/patch-CVE-2026-19843★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/errata/RHSA-2026:64768https://access.redhat.com/errata/RHSA-2026:64769https://access.redhat.com/errata/RHSA-2026:64779https://access.redhat.com/errata/RHSA-2026:64780https://access.redhat.com/errata/RHSA-2026:64782https://access.redhat.com/errata/RHSA-2026:64792https://access.redhat.com/errata/RHSA-2026:64793https://access.redhat.com/errata/RHSA-2026:65375https://access.redhat.com/security/cve/CVE-2026-19843https://bugzilla.redhat.com/show_bug.cgi?id=2515965