Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 91%

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a… (CVE-2026-19550)

0
Medium
Published: 08/11/2026 (08/11/2026, 21:33:11 UTC)
Source: GCVE Database

Description

A vulnerability in FreeIPA's trust-fetch-domains command allows an authenticated, non-privileged user to trigger a privileged Active Directory trust refresh using attacker-supplied credentials. This flaw arises because the command is gated by a read-only permission instead of a trust-administration permission, enabling unauthorized modification of trusted-domain and ID-range identity data in the IPA LDAP directory. The issue only affects FreeIPA servers with an established Active Directory trust. Exploitation requires network access from the IdM server to attacker-controlled infrastructure but no administrative privileges. The vulnerability has a medium severity with a CVSS score of 4.3.

CVSS v3.1

Score 4.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 17:23:34 UTC

Technical Analysis

CVE-2026-19550 is a vulnerability in FreeIPA where the trust-fetch-domains command is improperly protected by a read-only permission on the trust object rather than a trust-administration permission. This misconfiguration allows an authenticated, non-privileged IPA user to initiate a privileged Active Directory trust refresh using attacker-supplied server and credentials. As a result, an attacker can modify trusted-domain and ID-range identity data within the IPA LDAP directory without authorization. The flaw only impacts FreeIPA servers configured with an Active Directory cross-forest trust. Exploitation requires network reachability from the IdM server to attacker infrastructure but does not require delegated administrative privileges. The vulnerability is classified under CWE-863 (Incorrect Authorization) and has a CVSS v3.1 base score of 4.3 (medium severity). No known exploits are reported in the wild. No explicit patch or fix is currently documented by the vendor advisory, but a suggested mitigation is to restrict the default "System: Read Trust Information" permission to reduce exposure, though this may impact legitimate functionality and should be tested before deployment.

Potential Impact

An authenticated, non-privileged user on a FreeIPA server with Active Directory trust can trigger a privileged operation to refresh AD trust data using attacker-controlled credentials. This leads to unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory, impacting data integrity. There is no impact on confidentiality or availability reported. The vulnerability does not require administrative privileges but does require network access from the IdM server to attacker infrastructure. No known active exploitation is reported.

Mitigation Recommendations

No official patch or fix is currently documented in the vendor advisory. Administrators of FreeIPA servers with Active Directory trust should consider restricting the default "System: Read Trust Information" permission so it is not granted to all authenticated users. This compensating control reduces exposure but may affect legitimate read-only lookups such as SSSD subdomain support and should be tested in a controlled environment before production deployment. Monitor vendor advisories for any forthcoming official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-6xg7-8fr6-8p33
Osv Schema Version
1.4.0
Aliases
["CVE-2026-19550"]
Ecosystems
[]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a7c9b6dbf8831d539cdffc0

Added to database: 08/12/2026, 16:12:29 UTC

Last enriched: 08/12/2026, 17:23:34 UTC

Last updated: 08/13/2026, 03:41:00 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses