Junglewise Threat Intelligence

CVE-2026-79678: FreeIPA idp-add command authorization bypass allowing environment disclosure

CVE-2026-79678 · Severity: high · CVSS 8.1 · Published 2026-09-07

Executive brief

FreeIPA is an open-source identity management system used by enterprises to centralize authentication and access control. A flaw in the idp-add command allows any authenticated user to read sensitive server environment variables and trigger denial-of-service attacks by exhausting memory, bypassing proper authorization checks. This undermines the security model by exposing sensitive configuration and credentials to all users regardless of their privilege level.

Technical details

The vulnerability is a authorization bypass in FreeIPA's idp-add command where insufficiently validated --organization and --base-url parameters reach a constrained eval() call before LDAP access control checks are enforced. An authenticated IPA principal can exploit this by providing crafted input that executes code within the eval() context, allowing enumeration and reading of server process environment variables and triggering memory exhaustion via denial of service. The flaw affects all authenticated users regardless of privilege level, and patches are available via Red Hat security advisories (RHSA-2026:70564).

Affected products

  • FreeIPA FreeIPA

Timeline

  • 2026-09-07: disclosed
  • 2026-09-23: patched: Red Hat advisory RHSA-2026:70564

References