Skip to content
Red HatCVE-2026-19843

Red Hat 389-ds-base. The Cockpit 389 Console: command injection

High8.4CVE-2026-19843 · Published Sep 7, 2026 · updated Sep 8, 2026

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Directory Server 11
Product
all versionsNo fix yet
Red Hat Directory Server 12
Product
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat GLib2.: link following
Medium5.3Sep 7
Red Hat 389 Directory Server: denial of service
High7.5Sep 7
Red Hat 389 Directory Server: improper authentication
Critical9.8Sep 7
Red Hat: buffer overflow
High7.5Sep 7
Red Hat 389 Directory Server: improper access control
High7.5Sep 7
Red Hat FreeIPA: improper access control
High8.1Sep 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.