VulnSea

ipa vulnerabilities

CVEs whose affected-version data names the ipa package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-18147High· 8.1
1w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and comple…

TwilightRed Hat · ipaEPSS 0.29%via NVD
CVE-2026-79678High· 8.1
2w ago

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated…

TwilightRed Hat · ipaEPSS 0.47%via NVD
CVE-2026-76578Critical· 9.8PoC
2w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a r…

AbyssalRed Hat · ipaEPSS 0.45%via NVD
CVE-2026-53683Medium· 4.3
2w ago

Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed o…

SunlitRed Hat · ipaEPSS 0.16%via CVEORG
CVE-2019-14867High· 8.8
4y ago

Code injection in FreeIPA

Code injection in FreeIPA

Twilightipa · ipaEPSS 7.4%via OSV
ipa vulnerabilities (CVEs) · VulnSea