---
id: CVE-2026-18147
title: A flaw was found in FreeIPA
summary: >-
  A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit
  a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI
  password reset page. By enticing a victim to click a specially crafted link
  and comple…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: Red Hat
product: ipa
affected:
  - ipa (all versions)
  - ipa (all versions)
  - ipa
  - ipa (all versions)
  - 'idm:client/ipa (all versions)'
  - 'idm:DL1/ipa (all versions)'
published: '2026-09-09'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T04:17:41.600'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18147'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:70564'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18147'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2508181'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18147.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18147'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18147'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T18:28:44.286199Z'
epss: 0.00293
epssPercentile: 0.22125
ingestedAt: '2026-09-12T23:53:06.675Z'
patched:
  - enterprise_linux_appstream_v_9
  - enterprise_linux_codeready_linux_builder_v_9
---

## Overview

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:70564** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:70564)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18147.json)
