RHSA-2026:64768HighCVSS 8.4

Red Hat Security Advisory: 389-ds-base security update

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-19843 — 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor

🎯 Affected products3

  • Red Hat Directory Server 13.2 for RHEL 10
  • 389-ds-base-0:3.2.0-7.el10dsrv.src as a component of Red Hat Directory Server 13.2 for RHEL 10
  • cockpit-389-ds-0:3.2.0-7.el10dsrv.noarch as a component of Red Hat Directory Server 13.2 for RHEL 10

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict Cockpit 389 Console access to trusted administrators, and restrict delegated LDAP add/rename privileges to trusted accounts, until a fix is available. This issue only affects Red Hat Directory Server deployments that include the Cockpit console; plain RHEL 389-ds-base is not affected.

🔗 References (5)