Rocky Enterprise Software Foundation Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.
Security Fix(es):
ipa: FreeIPA: Unauthenticated DoS in /ipa/i18n_messages via Unbounded Request Body Read (CVE-2026-73198)
ipa: FreeIPA: Unauthenticated DoS in /ipa/migration/migration.py via Unbounded Request Body Read (CVE-2026-73197)
FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships (CVE-2026-11861)
freeipa: ipa: FreeIPA/IdM: Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL (CVE-2026-18147)
freeipa: ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes (CVE-2026-19550)
ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore (CVE-2026-13097)
ipa: freeipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI (CVE-2026-76578)
freeIPA: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service (CVE-2026-79678)
Bug Fix(es) and Enhancement(s):
[Cursor Automated] Include latest fixes in python3-ipatests package [Rocky Linux9.8] (JIRA:Rocky Linux-170987)
WebUI Hardening [rhel-9.8.z] (JIRA:Rocky Linux-238511)
ipa-otptoken-import hardening [rhel-9.8.z] (JIRA:Rocky Linux-238519)
host-mod: handle the password attribute when set with --setattr userpassword= [rhel-9.8.z] (JIRA:Rocky Linux-238523)
ipa env: support only simple * wildcard [rhel-9.8.z] (JIRA:Rocky Linux-238527)
ipa-epn: drop_privileges method is mixing uid and gid [rhel-9.8.z] (JIRA:Rocky Linux-238674)
ipa-migrate: require Replication Administrator privilege [rhel-9.8.z] (JIRA:Rocky Linux-238677)
ipa-migrate tool is renaming host records & host info in automount information [rhel-9.8.z] (JIRA:Rocky Linux-240767)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
{
"license": "CC-BY-4.0",
"license_url": "https://creativecommons.org/licenses/by/4.0/",
"source_advisory": "RHSA-2026:70564"
}