8.4
CVE-2026-19843
- EPSS 0.48%
- Veröffentlicht 07.09.2026 14:14:58
- Zuletzt bearbeitet 08.09.2026 20:17:29
- Erkennungen
389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 11.7 E4S for RHEL 8
Default Statusaffected
Version
8080020260903102346.f969626e
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 11.9 for RHEL 8
Default Statusaffected
Version
8100020260904171440.37ed7c03
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 12.2 E4S for RHEL 9
Default Statusaffected
Version
9020020260903155914.1674d574
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 12.4 E4S for RHEL 9
Default Statusaffected
Version
9040020260903102623.1674d574
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 12.6 EUS for RHEL 9
Default Statusaffected
Version
9060020260903100230.1674d574
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 12.8 for RHEL 9
Default Statusaffected
Version
9080020260908092641.1674d574
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 13.0 EUS for RHEL 10
Default Statusaffected
Version
0:3.0.6-4.el10dsrv
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 13.2 for RHEL 10
Default Statusaffected
Version
0:3.2.0-7.el10dsrv
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 11
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Directory Server 12
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 10
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 6
Default Statusunknown
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 8
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 9
Default Statusaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.399 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 8.4 | 1.7 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://access.redhat.com/security/cve/CVE-2026-19843
https://bugzilla.redhat.com/show_bug.cgi?id=2515965
https://access.redhat.com/errata/RHSA-2026:64779
https://access.redhat.com/errata/RHSA-2026:64792
https://access.redhat.com/errata/RHSA-2026:64768
https://access.redhat.com/errata/RHSA-2026:64769
https://access.redhat.com/errata/RHSA-2026:64782
https://access.redhat.com/errata/RHSA-2026:64780
https://access.redhat.com/errata/RHSA-2026:64793
https://access.redhat.com/errata/RHSA-2026:65375