Executive brief
389 Directory Server is an LDAP server used to manage directory information in enterprise environments. The Cockpit 389 Console, an administrative tool for managing LDAP entries, fails to properly escape distinguished names (DN) when constructing shell commands. An LDAP user with delegated entry creation or renaming privileges could inject shell metacharacters into a DN, causing arbitrary code execution with root privileges when an administrator views the malicious entry in the console.
Technical details
The vulnerability is a command injection flaw in the LDAP editor component of Cockpit 389 Console. The vulnerable code constructs an ldapsearch command by embedding an LDAP DN directly into a shell command string without proper escaping or quoting. An attacker with delegated LDAP privileges (ability to create or rename directory entries) can craft a malicious DN containing shell metacharacters (e.g., backticks, $(), pipes, semicolons). When a Cockpit administrator subsequently views the crafted entry in the 389 Console, the ldapsearch command executes with root privileges on the directory server host. The attack requires prior LDAP access but no network traversal to the management interface itself. A patch is available in 389-ds-base version 3.2.0-7.el10dsrv and later for Red Hat Directory Server 13.
Affected products
- Red Hat 389 Directory Server before 3.2.0-7.el10dsrv
- Red Hat Cockpit 389 Console before 3.2.0-7.el10dsrv
Timeline
- 2026-09-07: disclosed
- 2026-09-08: patched: Red Hat issued RHSA-2026:64768 with patched 389-ds-base 3.2.0-7.el10dsrv