CVE-2026-19843
8.4Red Hat · Directory Server
A command injection vulnerability exists in the Cockpit 389 Console due to improper sanitization of LDAP distinguished names, allowing an authenticated user to execute commands with root privileges.
Executive summary
A critical OS command injection flaw in the Red Hat Directory Server Cockpit console allows an authenticated user to achieve remote code execution with root privileges.
Vulnerability
This vulnerability is a command injection (CWE-78) occurring when the Cockpit 389 Console processes LDAP entry names. An attacker with delegated privileges to manage directory entries can inject malicious shell metacharacters that execute as root when viewed by an administrator.
Business impact
Successful exploitation grants an attacker full control over the directory server host with root-level permissions. Given the CVSS score of 8.4, this poses a severe risk of total system compromise, unauthorized data exfiltration, and potential lateral movement across the network, which could result in significant operational disruption and loss of sensitive identity data.
Remediation
Immediate Action: Update the affected Red Hat Directory Server packages to the fixed versions identified in the vendor errata (RHSA-2026:64768 and related advisories).
Proactive Monitoring: Monitor directory server access logs for unusual LDAP entry names containing shell metacharacters and audit Cockpit console logs for suspicious administrative activity.
Compensating Controls: Restrict administrative access to the Cockpit 389 Console to trusted personnel via network-level segmentation or IP whitelisting until patches are applied.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.
Analyst recommendation
This vulnerability represents a high-severity risk to infrastructure integrity due to the potential for privilege escalation to root. Administrators must prioritize the application of the provided Red Hat security updates across all affected RHEL environments to neutralize the threat of arbitrary command execution.
More Red Hat CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Red Hat would like to thank Andrew Rukin (Arenadata) for reporting this issue., per the CVE Program record.
- RHSA-2026:64768 Vendor advisory
- RHSA-2026:64769 Vendor advisory
- RHSA-2026:64779 Vendor advisory
- RHSA-2026:64780 Vendor advisory
- RHSA-2026:64782 Vendor advisory
- RHSA-2026:64792 Vendor advisory
- RHSA-2026:64793 Vendor advisory
- Vulnerability database entry