Shell Command Injection Vulnerability in Cockpit 389 Console by Red Hat
CVE-2026-19843
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-19843?
A vulnerability exists in the Cockpit 389 Console due to improper handling of LDAP entries in the ldapsearch command. This flaw allows an LDAP user with permissions to create or rename directory entries to inject shell metacharacters into the distinguished name (DN). When the Cockpit administrator accesses this entry, the constructed shell command executes with root privileges on the directory server, potentially leading to unauthorized actions and system compromise. This vulnerability underscores the need for stringent input validation and escaping mechanisms in web applications.
Affected Version(s)
Red Hat Directory Server 11.7 E4S for RHEL 8 8080020260903102346.f969626e
Red Hat Directory Server 11.9 for RHEL 8 8100020260904171440.37ed7c03
Red Hat Directory Server 12.2 E4S for RHEL 9 9020020260903155914.1674d574
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved