---
id: CVE-2026-19843
title: A flaw was found in 389-ds-base
summary: >-
  A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor
  constructs an ldapsearch command by embedding an LDAP entry's distinguished
  name (DN) into a shell command string without proper escaping. An LDAP user
  with delegated…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Red Hat
product: 'redhat-ds:11'
affected:
  - 'redhat-ds:11 (all versions)'
  - 'redhat-ds:11 (all versions)'
  - 'redhat-ds:12 (all versions)'
  - 'redhat-ds:12 (all versions)'
  - 'redhat-ds:12 (all versions)'
  - 'redhat-ds:12 (all versions)'
  - 389-ds-base (all versions)
  - 389-ds-base (all versions)
  - 389-ds-base (all versions)
  - 389-ds-base (all versions)
  - 389-ds-base (all versions)
  - 389-ds-base
  - 389-ds-base
  - '389-ds:1.4/389-ds-base (all versions)'
  - 389-ds-base
  - 389-ds-base (all versions)
patched:
  - directory_server_13_2_for_rhel 10
  - directory_server_11_9_for_rhel 8
  - directory_server_13_0_eus_for_rhel 10
  - directory_server_11_7_e4s_for_rhel 8
  - directory_server_12_2_e4s_for_rhel 9
  - directory_server_12_4_e4s_for_rhel 9
  - directory_server_12_6_eus_for_rhel 9
published: '2026-09-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:17:29.687'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19843'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:64768'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:64769'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:64779'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:64780'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:64782'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:64792'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:64793'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65375'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-19843'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515965'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19843.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-19843'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19843'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T14:06:40.847559Z'
epss: 0.0048
epssPercentile: 0.38788
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/gduma-phData/patch-CVE-2026-19843'
  checkedAt: '2026-09-26T09:05:39.676Z'
exploitAvailable: true
ingestedAt: '2026-09-08T15:33:26.978Z'
---

## Overview

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:64768** · Red Hat · fixed in: Red Hat Directory Server 13.2 for RHEL 10 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64768)
- **RHSA-2026:64793** · Red Hat · fixed in: Red Hat Directory Server 11.9 for RHEL 8 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64793)
- **RHSA-2026:64769** · Red Hat · fixed in: Red Hat Directory Server 13.0 EUS for RHEL 10 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64769)
- **RHSA-2026:64792** · Red Hat · fixed in: Red Hat Directory Server 11.7 E4S for RHEL 8 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64792)
- **RHSA-2026:64779** · Red Hat · fixed in: Red Hat Directory Server 12.2 E4S for RHEL 9 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64779)
- **RHSA-2026:64780** · Red Hat · fixed in: Red Hat Directory Server 12.4 E4S for RHEL 9 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64780)
- **RHSA-2026:64782** · Red Hat · fixed in: Red Hat Directory Server 12.6 EUS for RHEL 9 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64782)
- **Red Hat VEX** · Important · affected: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Enterprise Linux 10, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19843.json)
- **RHSA-2026:65375** · Red Hat · fixed in: Red Hat Directory Server 12.8 for RHEL 9 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65375)
