A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.

Project Subscriptions

Vendors Products
Directory Server Subscribe
Directory Server E2s Subscribe
Directory Server E4s Subscribe
Directory Server Eus Subscribe
Enterprise Linux Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Restrict Cockpit 389 Console access to trusted administrators, and restrict delegated LDAP add/rename privileges to trusted accounts, until a fix is available. This issue only affects Red Hat Directory Server deployments that include the Cockpit console; plain RHEL 389-ds-base is not affected.

History

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:directory_server:12.8::el9
References

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:directory_server:11.9::el8
cpe:/a:redhat:directory_server_e4s:12.4::el9
References

Tue, 08 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat directory Server E4s
Redhat directory Server Eus
CPEs cpe:/a:redhat:directory_server_e4s:11.7::el8
cpe:/a:redhat:directory_server_e4s:12.2::el9
cpe:/a:redhat:directory_server_eus:12.6::el9
Vendors & Products Redhat directory Server E4s
Redhat directory Server Eus
References

Tue, 08 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat directory Server E2s
CPEs cpe:/a:redhat:directory_server:13 cpe:/a:redhat:directory_server:13.2::el10
cpe:/a:redhat:directory_server_e2s:13.0::el10
Vendors & Products Redhat directory Server E2s
References

Tue, 08 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Title 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
First Time appeared Redhat
Redhat directory Server
Redhat enterprise Linux
Weaknesses CWE-78
CPEs cpe:/a:redhat:directory_server:11
cpe:/a:redhat:directory_server:12
cpe:/a:redhat:directory_server:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat directory Server
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-08T19:43:27.680Z

Reserved: 2026-08-14T08:02:44.101Z

Link: CVE-2026-19843

cve-icon Vulnrichment

Updated: 2026-09-08T14:06:44.400Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T15:17:31.287

Modified: 2026-09-08T20:17:29.687

Link: CVE-2026-19843

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-07T12:00:00Z

Links: CVE-2026-19843 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:30:06Z

Weaknesses