CVE-2026-19550: Incorrect Authorization in Red Hat Red Hat Enterprise Linux 9
CVE-2026-19550 is a high-severity authorization flaw in FreeIPA on Red Hat Enterprise Linux 9. It allows an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using attacker-supplied server and credentials. This results in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory. The vulnerability only affects IdM/FreeIPA servers with an established cross-forest trust with Active Directory. Exploitation requires no administrative privileges but does require an authenticated user account. The issue is fixed upstream, and administrators should apply the fix when available. Until then, restricting the "System: Read Trust Information" permission is a valid interim workaround, though it may impact SSSD subdomain support.
AI Analysis
Technical Summary
A flaw in FreeIPA's trust-fetch-domains command allows an authenticated, non-privileged IPA user to perform a privileged Active Directory trust refresh by exploiting incorrect authorization. The command is gated by a read-only permission instead of a trust-administration permission, enabling unauthorized modification of trusted-domain and ID-range identity data in the IPA LDAP directory. This vulnerability affects only servers with an active AD trust established via ipa-adtrust-install and ipa trust-add. Exploitation requires an authenticated non-admin user to trigger the command against an attacker-controlled server. Further impersonation of accounts in the trusted AD domain requires additional complex steps involving Kerberos traffic interception and cryptographic downgrades. The issue is fixed upstream, and administrators should apply the fix once available. Until then, restricting the "System: Read Trust Information" permission is a recommended interim mitigation.
Potential Impact
An authenticated, non-privileged IPA user can cause the IdM server to launch a privileged process that refreshes Active Directory trust using attacker-controlled servers and credentials. This leads to unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory, potentially compromising identity management integrity. The vulnerability requires an existing cross-forest trust with Active Directory and an authenticated user account but no administrative privileges. There are no known exploits in the wild at this time.
Mitigation Recommendations
This vulnerability is fixed upstream. Administrators should apply the official fix once it is available for their platform. Until the fix is applied, restricting the "System: Read Trust Information" permission so it is not granted to all authenticated users is a valid interim workaround. However, this restriction may affect SSSD subdomain support, which relies on the default permission breadth. No other mitigations are specified.
CVE-2026-19550: Incorrect Authorization in Red Hat Red Hat Enterprise Linux 9
Description
CVE-2026-19550 is a high-severity authorization flaw in FreeIPA on Red Hat Enterprise Linux 9. It allows an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using attacker-supplied server and credentials. This results in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory. The vulnerability only affects IdM/FreeIPA servers with an established cross-forest trust with Active Directory. Exploitation requires no administrative privileges but does require an authenticated user account. The issue is fixed upstream, and administrators should apply the fix when available. Until then, restricting the "System: Read Trust Information" permission is a valid interim workaround, though it may impact SSSD subdomain support.
CVSS v3.1
Score 8.2high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A flaw in FreeIPA's trust-fetch-domains command allows an authenticated, non-privileged IPA user to perform a privileged Active Directory trust refresh by exploiting incorrect authorization. The command is gated by a read-only permission instead of a trust-administration permission, enabling unauthorized modification of trusted-domain and ID-range identity data in the IPA LDAP directory. This vulnerability affects only servers with an active AD trust established via ipa-adtrust-install and ipa trust-add. Exploitation requires an authenticated non-admin user to trigger the command against an attacker-controlled server. Further impersonation of accounts in the trusted AD domain requires additional complex steps involving Kerberos traffic interception and cryptographic downgrades. The issue is fixed upstream, and administrators should apply the fix once available. Until then, restricting the "System: Read Trust Information" permission is a recommended interim mitigation.
Potential Impact
An authenticated, non-privileged IPA user can cause the IdM server to launch a privileged process that refreshes Active Directory trust using attacker-controlled servers and credentials. This leads to unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory, potentially compromising identity management integrity. The vulnerability requires an existing cross-forest trust with Active Directory and an authenticated user account but no administrative privileges. There are no known exploits in the wild at this time.
Mitigation Recommendations
This vulnerability is fixed upstream. Administrators should apply the official fix once it is available for their platform. Until the fix is applied, restricting the "System: Read Trust Information" permission so it is not granted to all authenticated users is a valid interim workaround. However, this restriction may affect SSSD subdomain support, which relies on the default permission breadth. No other mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6xg7-8fr6-8p33
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-19550"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7c9b6dbf8831d539cdffc0
Added to database: 08/12/2026, 16:12:29 UTC
Last enriched: 09/24/2026, 07:04:19 UTC
Last updated: 09/25/2026, 02:26:20 UTC
Views: 36
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.