CVE-2026-19550
Analyzed Analyzed - Analysis Complete

Privileged Trust Refresh in FreeIPA

Vulnerability report for CVE-2026-19550, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-25

Assigner: redhat-SADP

Description

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-25
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
redhat enterprise_linux 7.0
redhat enterprise_linux 8.0
redhat enterprise_linux 9.0
redhat enterprise_linux 10.0
freeipa freeipa to 4.13.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in FreeIPA allows an authenticated but non-privileged user to trigger a privileged Active Directory trust refresh. The user can supply attacker-controlled server and credentials, leading to unauthorized changes in trusted-domain and ID-range identity data stored in the IPA LDAP directory.

Detection Guidance

This vulnerability can be detected by reviewing IPA trust configurations and checking for unauthorized trust refresh operations. Look for unexpected modifications to trusted-domain or ID-range identity data in the IPA LDAP directory. Review logs for the trust-fetch-domains command usage by non-privileged users.

Impact Analysis

An attacker could manipulate identity data in the IPA LDAP directory, potentially causing disruptions in authentication, authorization, or data integrity within the FreeIPA environment. This may lead to unauthorized access or data exposure if exploited.

Compliance Impact

This vulnerability could compromise data integrity and access controls, which are critical for compliance with GDPR and HIPAA. Unauthorized modifications to identity data may result in violations of confidentiality, integrity, and availability requirements.

Mitigation Strategies

Update FreeIPA to the latest patched version to ensure the trust-fetch-domains command is properly gated by trust-administration permissions. Review and restrict permissions for non-privileged IPA users to prevent unauthorized trust refresh operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19550. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart