Red Hat Product Errata RHSA-2026:64768 - Security Advisory Issued: 2026-09-08 Updated: 2026-09-08 RHSA-2026:64768 - Security Advisory Overview Updated Packages Synopsis Important: 389-ds-base security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for 389-ds-base is now available for Red Hat Directory Server 13.2 for RHEL 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Additional Changes: For detailed information on changes in this release, see the Red Hat Directory Server 13.2 for RHEL 10 Release Notes linked from the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Directory Server 13 x86_64 Fixes BZ - 2515965 - CVE-2026-19843 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor CVEs CVE-2026-19843 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_directory_server/13/html/red_hat_directory_server_13_release_notes/index Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Directory Server 13 SRPM 389-ds-base-3.2.0-7.el10dsrv.src.rpm SHA-256: 0c16abe1aa4faa478822c28790de5bee595daf33ecb5adb8f3f8326f20400d64 x86_64 cockpit-389-ds-3.2.0-7.el10dsrv.noarch.rpm SHA-256: cf39ad6f4cac8eb9425965febb64db79044b4e8f7d0d6c6ff0ac3d6a989bdb18 cockpit-389-ds-3.2.0-7.el10dsrv.noarch.rpm SHA-256: cf39ad6f4cac8eb9425965febb64db79044b4e8f7d0d6c6ff0ac3d6a989bdb18 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This security update addresses CVE-2026-19843 (CVSS 8.4 High), a command injection vulnerability in the 389-ds-base Cockpit console where an unescaped LDAP DN in the LDAP editor can be exploited. The advisory affects Red Hat Directory Server 13.2 for RHEL 10, and the fix is provided in package version 389-ds-base-3.2.0-7.el10dsrv.