← All Advisories

CVE-2026-19550

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-19550

Key Details

CVECVE-2026-19550
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-09-28
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is high; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productssee table below
Classified asCWE-863 (Incorrect Authorization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
freeipafreeipa
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory. (NVD)

What to Do

Monitor Red Hat's and freeipa's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-19550
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-19550
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-19550