SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79678

HIGH · CVSS 8.1 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in FreeIPA's idp-add command, where inadequate validation of the --organization and --base-url inputs allows authenticated users to bypass LDAP access controls. This flaw enables any IPA principal to enumerate server environment variables and potentially induce a denial of service through memory exhaustion. Organizations using FreeIPA should prioritize patching this issue to safeguard against unauthorized data exposure and service disruption.

CVE
CVE-2026-79678
Severity
HIGH
CVSS
8.1
EPSS
0.47%

Original NVD Description

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.