{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-19843/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:red_hat:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.4,"id":"CVE-2026-19843"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389 Directory Server"],"_cs_severities":["high"],"_cs_tags":["cve-2026-19843","command-injection","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-19843 describes a critical command injection vulnerability in the 389 Directory Server's Cockpit 389 Console. The flaw stems from improper sanitization of LDAP entry distinguished names (DNs) when the console constructs and executes \u003ccode\u003eldapsearch\u003c/code\u003e commands. An attacker who has been delegated the authority to create or rename entries within the LDAP directory can inject arbitrary shell metacharacters into an entry's DN. When an administrator later logs into the Cockpit 389 Console and navigates to the view containing the malicious entry, the console's background process triggers the injection. Because the Cockpit 389 process operates with elevated permissions, the resulting command execution occurs with root privileges on the directory server host. This vulnerability effectively allows an attacker with low-level administrative access to escalate privileges to full system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains delegated LDAP write permissions for the target directory instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious Distinguished Name (DN) containing shell metacharacters such as backticks, semicolons, or pipe operators.\u003c/li\u003e\n\u003cli\u003eAttacker uses LDAP administrative tools to create or rename an existing entry using the crafted malicious DN.\u003c/li\u003e\n\u003cli\u003eAttacker waits for a system administrator to open the 389 Directory Server instance in the Cockpit 389 Console.\u003c/li\u003e\n\u003cli\u003eThe console interface iterates through directory entries and automatically executes a backend \u003ccode\u003eldapsearch\u003c/code\u003e call using the malicious DN string.\u003c/li\u003e\n\u003cli\u003eThe underlying shell interprets the injected metacharacters within the \u003ccode\u003eldapsearch\u003c/code\u003e command string.\u003c/li\u003e\n\u003cli\u003eThe system executes the injected payload as root, granting the attacker arbitrary code execution on the directory server host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full system compromise of the 389 Directory Server host, as the injected commands execute with root-level privileges. This enables attackers to exfiltrate the entire directory database, modify security credentials, install backdoors, or facilitate lateral movement within the network. The scope of impact is limited to organizations deploying 389 Directory Server with the Cockpit 389 Console management interface enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit existing LDAP entries for suspicious characters or unusually long strings in the 'distinguishedName' attribute using standard administrative tools.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on LDAP entry naming conventions to prevent the insertion of shell metacharacters.\u003c/li\u003e\n\u003cli\u003eRestrict delegation of entry creation or renaming privileges to a strictly controlled, minimal set of trusted users.\u003c/li\u003e\n\u003cli\u003eUpgrade 389 Directory Server and Cockpit 389 components to the patched version once released by the vendor.\u003c/li\u003e\n\u003cli\u003eMonitor host process-creation logs for \u003ccode\u003eldapsearch\u003c/code\u003e executions spawned by the Cockpit management user or web server process that contain suspicious shell arguments.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T15:34:00Z","date_published":"2026-09-07T15:34:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-19843/","summary":"A command injection vulnerability in the 389 Directory Server Cockpit console allows authenticated users with entry-creation privileges to achieve root-level command execution via crafted LDAP distinguished names.","title":"Command Injection in 389 Directory Server Cockpit Console","url":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-19843/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-19843","version":"https://jsonfeed.org/version/1.1"}