A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Administrators of IdM/FreeIPA servers with an Active Directory trust configured can reduce exposure by restricting the default "System: Read Trust Information" permission so it is no longer granted to all authenticated users. This is a suggested compensating control, and should be tested before applying in production, since "System: Read Trust Information" may be relied on by other legitimate read-only lookups (e.g. SSSD subdomain support, per the permission's own code comment).

History

Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
Title Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-863
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-11T20:46:42.019Z

Reserved: 2026-08-11T15:04:26.558Z

Link: CVE-2026-19550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T21:17:35.087

Modified: 2026-08-11T21:17:35.087

Link: CVE-2026-19550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses