CVE-2026-19843: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Red Hat Red Hat Directory Server 13.0 EUS for RHEL 10
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
AI Analysis
Technical Summary
The vulnerability in 389-ds-base's Cockpit 389 Console LDAP editor arises from improper neutralization of special elements in an OS command (CWE-78). Specifically, the LDAP editor constructs an ldapsearch shell command embedding an LDAP entry's DN without escaping shell metacharacters. An LDAP user with delegated privileges to create or rename directory entries can insert shell metacharacters into the DN. When a Cockpit administrator views this entry, the shell command executes with root privileges on the directory server host. This leads to arbitrary command execution, compromising confidentiality, integrity, and availability of the host. Exploitation requires both delegated LDAP write privileges and a privileged Cockpit operator viewing the entry. The issue only affects Red Hat Directory Server deployments with the Cockpit 389 Console subpackage; plain RHEL 389-ds-base is not affected. No official fix or patch is currently confirmed. The vendor advisory recommends restricting access to trusted administrators and limiting delegated LDAP privileges until a fix is available.
Potential Impact
Successful exploitation allows an attacker with delegated LDAP create or rename privileges to execute arbitrary OS commands with root privileges on the directory server host. This compromises the confidentiality, integrity, and availability of the host system. The attack requires a second condition: a privileged Cockpit administrator must view the malicious LDAP entry, triggering command execution. Neither condition alone is sufficient for exploitation. This vulnerability can lead to unauthorized code execution, data modification, and potential denial of service on the affected host.
Mitigation Recommendations
No official fix or patch is currently available. Until a fix is released, Red Hat recommends restricting access to the Cockpit 389 Console to trusted administrators only and limiting delegated LDAP add/rename privileges to trusted accounts. This reduces the risk of exploitation by ensuring only trusted users can create or rename LDAP entries and only trusted operators can view them. Plain Red Hat Enterprise Linux installations without the Cockpit 389 Console subpackage are not affected and require no action.
CVE-2026-19843: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Red Hat Red Hat Directory Server 13.0 EUS for RHEL 10
Description
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
CVSS v3.1
Score 8.4high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in 389-ds-base's Cockpit 389 Console LDAP editor arises from improper neutralization of special elements in an OS command (CWE-78). Specifically, the LDAP editor constructs an ldapsearch shell command embedding an LDAP entry's DN without escaping shell metacharacters. An LDAP user with delegated privileges to create or rename directory entries can insert shell metacharacters into the DN. When a Cockpit administrator views this entry, the shell command executes with root privileges on the directory server host. This leads to arbitrary command execution, compromising confidentiality, integrity, and availability of the host. Exploitation requires both delegated LDAP write privileges and a privileged Cockpit operator viewing the entry. The issue only affects Red Hat Directory Server deployments with the Cockpit 389 Console subpackage; plain RHEL 389-ds-base is not affected. No official fix or patch is currently confirmed. The vendor advisory recommends restricting access to trusted administrators and limiting delegated LDAP privileges until a fix is available.
Potential Impact
Successful exploitation allows an attacker with delegated LDAP create or rename privileges to execute arbitrary OS commands with root privileges on the directory server host. This compromises the confidentiality, integrity, and availability of the host system. The attack requires a second condition: a privileged Cockpit administrator must view the malicious LDAP entry, triggering command execution. Neither condition alone is sufficient for exploitation. This vulnerability can lead to unauthorized code execution, data modification, and potential denial of service on the affected host.
Mitigation Recommendations
No official fix or patch is currently available. Until a fix is released, Red Hat recommends restricting access to the Cockpit 389 Console to trusted administrators only and limiting delegated LDAP add/rename privileges to trusted accounts. This reduces the risk of exploitation by ensuring only trusted users can create or rename LDAP entries and only trusted operators can view them. Plain Red Hat Enterprise Linux installations without the Cockpit 389 Console subpackage are not affected and require no action.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-14T08:02:44.101Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-19843","vendor":"Red Hat"}]
Threat ID: 6a9ec8b6acd9273b49c4cf90
Added to database: 09/07/2026, 14:22:46 UTC
Last enriched: 09/07/2026, 14:37:31 UTC
Last updated: 09/08/2026, 02:15:02 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.