Privilege Escalation via LDAP Shell Injection in 389 Console
CVE-2026-19843 Published on September 7, 2026
389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.
Vulnerability Analysis
CVE-2026-19843 can be exploited with network access, requires user interaction and user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public. 32 days later.
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-19843 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-19843
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Directory Server 11.7 E4S for RHEL 8:- Version 8080020260903102346.f969626e and below * is unaffected.
- Version 8100020260904171440.37ed7c03 and below * is unaffected.
- Version 9020020260903155914.1674d574 and below * is unaffected.
- Version 9040020260903102623.1674d574 and below * is unaffected.
- Version 9060020260903100230.1674d574 and below * is unaffected.
- Version 9080020260908092641.1674d574 and below * is unaffected.
- Version 0:3.0.6-4.el10dsrv and below * is unaffected.
- Version 0:3.2.0-7.el10dsrv and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.