Description
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Published: 2026-09-07
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Restrict Cockpit 389 Console access to trusted administrators, and restrict delegated LDAP add/rename privileges to trusted accounts, until a fix is available. This issue only affects Red Hat Directory Server deployments that include the Cockpit console; plain RHEL 389-ds-base is not affected.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat directory Server E4s
Redhat directory Server Eus
CPEs cpe:/a:redhat:directory_server_e4s:11.7::el8
cpe:/a:redhat:directory_server_e4s:12.2::el9
cpe:/a:redhat:directory_server_eus:12.6::el9
Vendors & Products Redhat directory Server E4s
Redhat directory Server Eus
References

Tue, 08 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat directory Server E2s
CPEs cpe:/a:redhat:directory_server:13 cpe:/a:redhat:directory_server:13.2::el10
cpe:/a:redhat:directory_server_e2s:13.0::el10
Vendors & Products Redhat directory Server E2s
References

Tue, 08 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Title 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
First Time appeared Redhat
Redhat directory Server
Redhat enterprise Linux
Weaknesses CWE-78
CPEs cpe:/a:redhat:directory_server:11
cpe:/a:redhat:directory_server:12
cpe:/a:redhat:directory_server:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat directory Server
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Directory Server Directory Server E2s Directory Server E4s Directory Server Eus Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-08T03:03:42.207Z

Reserved: 2026-08-14T08:02:44.101Z

Link: CVE-2026-19843

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T15:17:31.287

Modified: 2026-09-08T04:17:21.903

Link: CVE-2026-19843

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-07T12:00:00Z

Links: CVE-2026-19843 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:30:06Z

Weaknesses