Security Flaw in FreeIPA's idp-add Command Exposes Server Environment Variables
CVE-2026-79678
8.1HIGH
What is CVE-2026-79678?
A vulnerability exists in FreeIPA's idp-add command where insufficient validation of the --organization and --base-url parameters can lead to critical issues. This flaw allows authenticated users, irrespective of their privilege level, to exploit a constrained eval() call before LDAP access control checks are applied. Consequently, the attacker can enumerate and access sensitive environment variables of the server process, which may result in service disruption due to memory exhaustion, posing a significant risk to the stability and security of the affected systems.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Calif.io (in collaboration with Anthropic) for reporting this issue.