---
id: CVE-2026-79678
title: >-
  A flaw was found in FreeIPA's idp-add command, where insufficiently validated
  --organization/--base-url input reaches a constrained eval() call before the
  corresponding LDAP access control check is enforced
summary: >-
  A flaw was found in FreeIPA's idp-add command, where insufficiently validated
  --organization/--base-url input reaches a constrained eval() call before the
  corresponding LDAP access control check is enforced. This allows any
  authenticated…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-95
vendor: Red Hat
product: ipa
affected:
  - ipa (all versions)
  - ipa (all versions)
  - ipa
  - ipa
  - 'idm:client/ipa (all versions)'
  - 'idm:DL1/ipa (all versions)'
  - ipa (all versions)
published: '2026-09-07'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T04:17:59.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79678'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:70564'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-79678'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2523356'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79678.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-79678'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79678'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T14:09:01.514900Z'
epss: 0.00595
epssPercentile: 0.46099
ingestedAt: '2026-09-08T15:33:26.977Z'
patched:
  - enterprise_linux_appstream_v_9
  - enterprise_linux_codeready_linux_builder_v_9
---

## Overview

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79678.json)
- **RHSA-2026:70564** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:70564)
