CVE-2026-79678

NameCVE-2026-79678
DescriptionA flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freeipa (PTS)bookworm4.9.11-1vulnerable
trixie4.12.4-1vulnerable
sid4.13.1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freeipasource(unstable)(unfixed)unimportant

Notes

FreeIPA in Debian only builds the client packages, not the server
https://bugzilla.redhat.com/show_bug.cgi?id=2523356

Search for package or bug name: Reporting problems