High severity8.2NVD Advisory· Published Aug 11, 2026· Updated Aug 25, 2026
CVE-2026-19550
CVE-2026-19550
Description
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- osv-coords8 versionspkg:apk/chainguard/py3.13-ipapythonpkg:apk/chainguard/freeipapkg:apk/chainguard/freeipa-docpkg:apk/chainguard/py3.13-ipaclientpkg:apk/chainguard/py3.13-ipatestspkg:apk/chainguard/py3.13-ipalibpkg:apk/chainguard/py3.13-ipaplatformpkg:apk/chainguard/py3.13-ipaserver
< 4.13.3-r0+ 7 more
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-19550nvdVendor AdvisoryMitigation
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.