Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-79678

Опубликовано: 07 сент. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.

EPSS

Процентиль: 39%
0.00466
Низкий

8.1 High

CVSS3

Дефекты

CWE-95

Связанные уязвимости

CVSS3: 8.1
ubuntu
10 дней назад

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.

CVSS3: 8.1
redhat
10 дней назад

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.

CVSS3: 8.1
debian
10 дней назад

A flaw was found in FreeIPA's idp-add command, where insufficiently va ...

CVSS3: 8.1
github
10 дней назад

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.

EPSS

Процентиль: 39%
0.00466
Низкий

8.1 High

CVSS3

Дефекты

CWE-95