Confidentiality Flaw in FreeIPA's idp-add Command Exposes Credentials

Confidentiality Flaw in FreeIPA's idp-add Command Exposes Credentials

First seen 8 Sep 2026, 00:32 UTC Redpacketsecurityaccess.redhat.com 57.8

Article Content

Browse articles
ThreatCluster

A vulnerability identified as CVE-2026-79678 in FreeIPA's idp-add command allows any authenticated IPA principal to access environment variables and cause denial of service through memory exhaustion. The flaw arises from insufficient validation of input parameters, allowing unauthorized access to sensitive data in container deployments. While the flaw does not enable arbitrary code execution, it poses a significant risk, especially in environments where sensitive credentials are stored in environment variables. The vulnerability is rated Important due to its potential for systematic exploitation and denial-of-service capabilities. Administrators are advised to upgrade to a fixed package and verify that sensitive credentials do not persist in the server process environment. The flaw was published on September 7, 2026, and is currently not known to be actively exploited.

Key Points: • CVE-2026-79678 allows environment variable access and denial of service. • The flaw affects authenticated users, regardless of privilege level. • Immediate upgrade to a fixed package is required to mitigate the risk.

Ask AI about this cluster

Timeline

2026-09-07
CVE-2026-79678 published
Red Hat disclosed a vulnerability in FreeIPA's idp-add command affecting authenticated users.
Redpacketsecurity
2026-09-08
Red Hat issues advisory
Red Hat released details on the vulnerability and recommended immediate upgrades for affected systems.
access.redhat.com