RHSA-2026:64782HighCVSS 8.4
Red Hat Security Advisory: redhat-ds:12 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-19843 — 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor
🎯 Affected products3
- Red Hat Directory Server 12.6 EUS for RHEL 9
- 389-ds-base-0:2.6.1-4.module+el9dsrv+24810+65883465.src (redhat-ds:12) as a component of Red Hat Directory Server 12.6 EUS for RHEL 9
- cockpit-389-ds-0:2.6.1-4.module+el9dsrv+24810+65883465.noarch (redhat-ds:12) as a component of Red Hat Directory Server 12.6 EUS for RHEL 9
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict Cockpit 389 Console access to trusted administrators, and restrict delegated LDAP add/rename privileges to trusted accounts, until a fix is available. This issue only affects Red Hat Directory Server deployments that include the Cockpit console; plain RHEL 389-ds-base is not affected.