RHSA-2026:64768HighCVSS 8.4
Red Hat Security Advisory: 389-ds-base security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-19843 — 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor
🎯 Affected products3
- Red Hat Directory Server 13.2 for RHEL 10
- 389-ds-base-0:3.2.0-7.el10dsrv.src as a component of Red Hat Directory Server 13.2 for RHEL 10
- cockpit-389-ds-0:3.2.0-7.el10dsrv.noarch as a component of Red Hat Directory Server 13.2 for RHEL 10
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict Cockpit 389 Console access to trusted administrators, and restrict delegated LDAP add/rename privileges to trusted accounts, until a fix is available. This issue only affects Red Hat Directory Server deployments that include the Cockpit console; plain RHEL 389-ds-base is not affected.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:64768
- externalhttps://docs.redhat.com/en/documentation/red_hat_directory_server/13/html/red_hat_directory_server_13_release_notes/index
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515965
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_64768.json