Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes
Published Aug 11, 2026
8.2
HIGHCVSS 3.1
EPSS 0.29%
Description
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
|
Configuration 1
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
ipa
Affected
Red Hat Enterprise Linux 6
ipa
Not affected
Red Hat Enterprise Linux 7
ipa
Affected
Red Hat Enterprise Linux 8
ipa
Affected
Red Hat Enterprise Linux 9
ipa
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 6 | ipa | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 8 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 9 | ipa | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
This issue is fixed upstream. Administrators should apply this fix once available for their platform. Until then, the previously suggested compensating control (restricting "System: Read Trust Information" so it is not granted to all authenticated users) remains a valid interim workaround, with the same caveat that doing so may affect SSSD subdomain support, which relies on that permission's default breadth.
Red Hat statement
This flaw only affects Identity Management (IdM/FreeIPA) servers where a cross-forest trust with Active Directory has been established (via ipa-adtrust-install and ipa trust-add). Servers without an active AD trust are not affected, since the trust object and the ADTRUST component required to reach the vulnerable code path do not exist in that configuration. Exploitation requires an ordinary, non-administrative IdM user account to trigger the vulnerable trust-fetch-domains command against a server of the attacker's choosing — no delegated administrative privilege of any kind is required. On its own, this lets an authenticated non-admin user force the IdM server to launch a privileged helper process and initiate a network connection to attacker-controlled infrastructure. Impersonating accounts in the trusted Active Directory domain — additionally requires the attacker to intercept and relay the resulting Kerberos authentication traffic, force a downgrade to the weaker encrypted-timestamp pre-authentication mechanism, and successfully recover the trust's interrealm secret through that downgrade.
Red Hat mitigation
This issue is fixed upstream. Administrators should apply this fix once available for their platform. Until then, the previously suggested compensating control (restricting "System: Read Trust Information" so it is not granted to all authenticated users) remains a valid interim workaround, with the same caveat that doing so may affect SSSD subdomain support, which relies on that permission's default breadth.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 12, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.29% (0.00285) | 19.00th | v5 (v2026.06.15) |
| Aug 12, 2026 | 0.19% (0.00193) | 9.19th | v5 (v2026.06.15) |
References (6)
- https://access.redhat.com/errata/RHSA-2026:70564 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72279 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-19550 vdb-entryx_refsource_REDHATVendor AdvisoryMitigation
- https://bugzilla.redhat.com/show_bug.cgi?id=2514019 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-19550
- https://www.cve.org/CVERecord?id=CVE-2026-19550
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:70564 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:72279 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-19550 | vdb-entryx_refsource_REDHATVendor AdvisoryMitigation | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2514019 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-19550 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-19550 |
Change history (0)
No recorded changes yet.