Skip to main content
EPSS 0.4%top 73%

CVE-2026-19550: Incorrect Authorization in Red Hat Red Hat Enterprise Linux 9

0
High
Published: 08/11/2026 (08/11/2026, 20:46:42 UTC)
Source: GCVE Database
Vendor/Project: Red Hat
Product: Red Hat Enterprise Linux 9

Description

CVE-2026-19550 is a high-severity authorization flaw in FreeIPA on Red Hat Enterprise Linux 9. It allows an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using attacker-supplied server and credentials. This results in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory. The vulnerability only affects IdM/FreeIPA servers with an established cross-forest trust with Active Directory. Exploitation requires no administrative privileges but does require an authenticated user account. The issue is fixed upstream, and administrators should apply the fix when available. Until then, restricting the "System: Read Trust Information" permission is a valid interim workaround, though it may impact SSSD subdomain support.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 07:04:19 UTC

Technical Analysis

A flaw in FreeIPA's trust-fetch-domains command allows an authenticated, non-privileged IPA user to perform a privileged Active Directory trust refresh by exploiting incorrect authorization. The command is gated by a read-only permission instead of a trust-administration permission, enabling unauthorized modification of trusted-domain and ID-range identity data in the IPA LDAP directory. This vulnerability affects only servers with an active AD trust established via ipa-adtrust-install and ipa trust-add. Exploitation requires an authenticated non-admin user to trigger the command against an attacker-controlled server. Further impersonation of accounts in the trusted AD domain requires additional complex steps involving Kerberos traffic interception and cryptographic downgrades. The issue is fixed upstream, and administrators should apply the fix once available. Until then, restricting the "System: Read Trust Information" permission is a recommended interim mitigation.

Potential Impact

An authenticated, non-privileged IPA user can cause the IdM server to launch a privileged process that refreshes Active Directory trust using attacker-controlled servers and credentials. This leads to unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory, potentially compromising identity management integrity. The vulnerability requires an existing cross-forest trust with Active Directory and an authenticated user account but no administrative privileges. There are no known exploits in the wild at this time.

Mitigation Recommendations

This vulnerability is fixed upstream. Administrators should apply the official fix once it is available for their platform. Until the fix is applied, restricting the "System: Read Trust Information" permission so it is not granted to all authenticated users is a valid interim workaround. However, this restriction may affect SSSD subdomain support, which relies on the default permission breadth. No other mitigations are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-6xg7-8fr6-8p33
Osv Schema Version
1.4.0
Aliases
["CVE-2026-19550"]
Database Specific Severity
MODERATE
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a7c9b6dbf8831d539cdffc0

Added to database: 08/12/2026, 16:12:29 UTC

Last enriched: 09/24/2026, 07:04:19 UTC

Last updated: 09/25/2026, 02:26:20 UTC

Views: 36

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses