RHSA-2026:65375HighCVSS 8.4
Red Hat Security Advisory: redhat-ds:12 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-19843 — 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor
🎯 Affected products3
- Red Hat Directory Server 12.8 for RHEL 9
- 389-ds-base-0:2.8.0-7.module+el9dsrv+24844+8988a132.src (redhat-ds:12) as a component of Red Hat Directory Server 12.8 for RHEL 9
- cockpit-389-ds-0:2.8.0-7.module+el9dsrv+24844+8988a132.noarch (redhat-ds:12) as a component of Red Hat Directory Server 12.8 for RHEL 9
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict Cockpit 389 Console access to trusted administrators, and restrict delegated LDAP add/rename privileges to trusted accounts, until a fix is available. This issue only affects Red Hat Directory Server deployments that include the Cockpit console; plain RHEL 389-ds-base is not affected.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:65375
- externalhttps://docs.redhat.com/en/documentation/red_hat_directory_server/12/html/red_hat_directory_server_12_release_notes/index
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515965
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65375.json