A flaw was found in the ipa-enrollment SLAPI plugin. (CVE-2026-73199)
Description
A null pointer dereference vulnerability exists in the ipa-enrollment SLAPI plugin. A remote authenticated attacker can exploit this by sending a malformed LDAP extended operation that omits the JOIN_OID request value, causing the server to crash and resulting in a denial of service. The vulnerability has a CVSS score of 6.5 (medium severity). No official patch is currently available. Mitigations include restricting network access to the LDAP service to trusted clients and disabling the ipa-enrollment plugin if host enrollment is not needed.
CVSS v3.1
Score 6.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-73199 is a null pointer dereference vulnerability in the ipa-enrollment SLAPI plugin. An authenticated remote client can trigger a server crash by sending a malformed LDAP extended operation that omits the JOIN_OID request value in the ipa-enrollment extended operation. This causes a denial of service due to the null pointer dereference. The vulnerability has a CVSS 3.1 base score of 6.5 with network attack vector, low attack complexity, low privileges required, no user interaction, unchanged scope, no confidentiality or integrity impact, and high availability impact. No known exploits are reported in the wild. The vendor advisory from Red Hat recommends restricting LDAP network access to trusted clients and disabling the ipa-enrollment plugin if not required. No official patch or fix is currently available according to the advisory.
Potential Impact
The vulnerability allows a remote authenticated attacker to cause a denial of service by crashing the LDAP server process through a null pointer dereference. There is no impact on confidentiality or integrity. The availability impact is high due to the server crash. No known active exploitation has been reported.
Mitigation Recommendations
No official patch or fix is currently available. Red Hat recommends restricting network access to the LDAP service to trusted clients only by configuring firewall rules to allow connections only from known, trusted IP addresses or subnets. Additionally, if host enrollment functionality is not required, disabling the ipa-enrollment SLAPI plugin removes this attack surface and mitigates the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mjqg-mjqw-9xv8
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-73199"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a870a4eacd9273b49b584ce
Added to database: 08/20/2026, 14:08:14 UTC
Last enriched: 08/20/2026, 14:14:58 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.