CVE-2019-14867High· 8.8▾ TwilightCode injection in FreeIPA
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 1.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
6.3%
6.3% → 7.4%
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.
ipa >= 4.6.2, < 4.6.7ipa >= 4.7.0, < 4.7.4ipa >= 4.8.0, < 4.8.3freeipa >= 4.6.2, < 4.6.7freeipa >= 4.7.0, < 4.7.4freeipa >= 4.8.0, < 4.8.3Upgrade to a patched release:
ipa 4.6.7ipa 4.7.4ipa 4.8.3freeipa 4.6.7freeipa 4.7.4freeipa 4.8.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53683Medium· 4.3Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html
CVE-2026-18147High· 8.1A flaw was found in FreeIPA
CVE-2026-76578Critical· 9.8A flaw was found in FreeIPA
CVE-2026-79678High· 8.1A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced