Executive brief
FreeIPA is an open-source identity management system used by enterprises to centralize authentication and access control. A flaw in the idp-add command allows any authenticated user to read sensitive server environment variables and trigger denial-of-service attacks by exhausting memory, bypassing proper authorization checks. This undermines the security model by exposing sensitive configuration and credentials to all users regardless of their privilege level.
Technical details
The vulnerability is a authorization bypass in FreeIPA's idp-add command where insufficiently validated --organization and --base-url parameters reach a constrained eval() call before LDAP access control checks are enforced. An authenticated IPA principal can exploit this by providing crafted input that executes code within the eval() context, allowing enumeration and reading of server process environment variables and triggering memory exhaustion via denial of service. The flaw affects all authenticated users regardless of privilege level, and patches are available via Red Hat security advisories (RHSA-2026:70564).
Affected products
- FreeIPA FreeIPA
Timeline
- 2026-09-07: disclosed
- 2026-09-23: patched: Red Hat advisory RHSA-2026:70564