Upstream information
Description
A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
| CVSS detail | CNA (Red Hat) |
|---|---|
| Base Score | 8.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | None |
| Availability Impact | High |
| CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- RHSA-2026:70564, published Mon Sep 28 15:07:47 UTC 2026
- RHSA-2026:72279, published Tue Sep 29 15:07:42 UTC 2026
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Liberty Linux 10 |
| Patchnames: RHSA-2026:72279 (x86_64) |
| SUSE Liberty Linux 9 |
| Patchnames: RHSA-2026:70564 (x86_64) |
SUSE Timeline for this CVE
CVE page created: Mon Sep 28 17:44:05 2026CVE page last modified: Wed Sep 30 12:02:48 2026