Junglewise Threat Intelligence

CVE-2026-53683: FreeIPA Web UI open redirect in reset_password.html

CVE-2026-53683 · Severity: medium · CVSS 4.3 · Published 2026-09-02

Vendors: Red Hat.

Executive brief

FreeIPA is an identity and access management system used by organizations to manage user authentication and authorization. An attacker can craft a link that redirects users to a malicious website after they complete a password reset, enabling phishing attacks that steal credentials or trick users into downloading malware.

Technical details

The vulnerability is an open redirect (CWE-601) in reset_password.html. The page parses the 'url' query string parameter and directly passes it to window.location without validation or allowlisting, enabling arbitrary client-side redirection after password reset. The 'delay' parameter allows an attacker to optionally delay the redirect. Attack requires user interaction (following a crafted link), and exploitation is typically used for phishing or drive-by download attacks. Red Hat recommends eliminating arbitrary redirects, allowlisting same-origin paths, or using server-generated signed tokens instead of raw URLs.

Affected products

  • Red Hat FreeIPA

Timeline

  • 2026-09-02: disclosed

References