A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

This issue is fixed upstream. Administrators should apply this fix once available for their platform. Until then, the previously suggested compensating control (restricting "System: Read Trust Information" so it is not granted to all authenticated users) remains a valid interim workaround, with the same caveat that doing so may affect SSSD subdomain support, which relies on that permission's default breadth.

History

Thu, 20 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
Title Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-863
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-20T16:35:40.198Z

Reserved: 2026-08-11T15:04:26.558Z

Link: CVE-2026-19550

cve-icon Vulnrichment

Updated: 2026-08-12T12:58:44.447Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T21:17:35.087

Modified: 2026-08-20T17:17:28.107

Link: CVE-2026-19550

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-11T15:04:44Z

Links: CVE-2026-19550 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:38Z

Weaknesses