Red HatCVE-2026-18147
Red Hat FreeIPA. An unauthenticated remote attacker: cross-site scripting
High8.1CVE-2026-18147 · Published Sep 9, 2026 · updated Sep 24, 2026
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 9 | Red Hat memcached cache plugin of the community: remote code execution | High8.1 | No fix yet |
| Sep 9 | Red Hat Enterprise Linux 10: out-of-bounds read | Medium4.3 | No fix yet |
| Sep 9 | Two case-insensitive comparisons on request-derived usernames outside the main... | Low3.0 | No fix yet |
| Sep 9 | A flaw was found in SSSD's IdP authentication provider | High7.5 | No fix yet |
| Sep 9 | Red Hat Ceph Storage 5: improper certificate validation | Medium6.8 | No fix yet |
| Sep 9 | Red Hat bubblewrap. During sandbox setup: link following | High8.8 | No fix yet |