Back Redpacketsecurity CVE Alert: CVE-2026-79678 – Red Hat
A flaw was found in FreeIPA’s idp-add command, where insufficiently validated –organization/–base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.
High risk: prioritise rapid remediation because any authenticated, low-privilege identity-management user may trigger serious confidentiality loss or service disruption; KEV, SSVC exploitation status, PoC availability and EPSS are not provided, so active exploitation cannot be confirmed.
The issue can expose process-environment data, potentially revealing bootstrap secrets, service credentials or configuration details that support follow-on compromise. Deliberate resource exhaustion could interrupt authentication and dependent services, creating a meaningful availability and business-continuity impact even without administrative privileges.
### Most likely attack path
An attacker first obtains or abuses any valid account, then sends crafted network input to the identity-provider creation operation. The path requires low effort, no user interaction and limited privilege, while unchanged scope suggests the immediate impact remains within the affected service; disclosed credentials could nevertheless enable lateral movement into connected systems.
### Who is most exposed
Internet-reachable or broadly accessible identity-management servers, particularly those issuing accounts to contractors, users or automated systems, face the greatest exposure. Container deployments deserve additional scrutiny where initial setup secrets may remain in the running process environment.
Review audit logs for unusual identity-provider creation attempts by ordinary users.
Alert on malformed organisation or base-URL parameters and repeated failures.
Monitor unexpected process-memory growth, service restarts and authentication outages.
Inspect environment-variable access, secret exposure and subsequent credential use.
Correlate suspicious identity activity with LDAP, host and network telemetry.
### Mitigation and prioritisation
Upgrade to the vendor-fixed package as soon as available; do not defer for routine patch cycles.
Until then, restrict network access and remove unnecessary authenticated accounts and privileges.
Rotate any credentials that may have existed in process environments, especially container bootstrap secrets.
Test remediation in a representative identity-management cluster and plan controlled failover.
Obtain EPSS, KEV, SSVC and PoC status to refine urgency; current absence is an assessment gap.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
