Description
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
Published: 2026-08-11
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The trust-fetch-domains command is protected by a read-only trust object permission rather than a trust‑administration permission, allowing any authenticated but non‑privileged IPA user to trigger an Active Directory trust refresh controlled by the attacker. This results in unauthorized writes to trusted‑domain and ID‑range identity data in the LDAP directory, compromising trust relationship integrity and potentially enabling further exploitation of the domain. The flaw is a classic privilege‑escalation weakness (CWE‑863).

Affected Systems

Red Hat Enterprise Linux 6 through 10 running FreeIPA with an Active Directory trust configured are affected. The issue arises when the server’s trust‑fetch-domains command is invoked by a non‑privileged user, regardless of specific FreeIPA versions beyond those operating systems.

Risk and Exploitability

With a CVSS score of 8.2 the vulnerability poses a high risk, and the EPSS score of less than 1% indicates a very low probability of exploitation at present. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated LDAP user who has limited privileges but can send commands to the server; thus the exploitation requires an authenticated session, not a local or OS privilege escalation.

Generated by OpenCVE AI on August 22, 2026 at 10:09 UTC.

Remediation

Vendor Workaround

This issue is fixed upstream. Administrators should apply this fix once available for their platform. Until then, the previously suggested compensating control (restricting "System: Read Trust Information" so it is not granted to all authenticated users) remains a valid interim workaround, with the same caveat that doing so may affect SSSD subdomain support, which relies on that permission's default breadth.


OpenCVE Recommended Actions

  • Restrict the "System: Read Trust Information" permission so that it is granted only to privileged administrator groups rather than all authenticated users, thereby preventing the misuse of trust-fetch-domains.
  • Conduct a comprehensive test to ensure that reducing this permission does not break legitimate read‑only operations such as SSSD subdomain support or other services that rely on the permission.
  • Monitor FreeIPA event logs and LDAP activity for any anomalous trust refresh attempts, and apply any Red Hat advisory patches as they become available.

Generated by OpenCVE AI on August 22, 2026 at 10:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Freeipa
Freeipa freeipa
CPEs cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Freeipa
Freeipa freeipa

Thu, 20 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
Title Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-863
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Freeipa Freeipa
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-20T16:35:40.198Z

Reserved: 2026-08-11T15:04:26.558Z

Link: CVE-2026-19550

cve-icon Vulnrichment

Updated: 2026-08-12T12:58:44.447Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T21:17:35.087

Modified: 2026-08-25T14:32:59.970

Link: CVE-2026-19550

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-11T15:04:44Z

Links: CVE-2026-19550 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T10:15:04Z

Weaknesses