← All Advisories

CVE-2026-79678

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-79678

Key Details

CVECVE-2026-79678
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-29
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, and Red Hat Enterprise Linux 9
Classified asCWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-79678
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-79678