Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-19550
Red Hat Red Hat Enterprise Linux 10 — Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H L N C H H N 8.2 .0029 19.1 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 10 unspecified 0:4.13.4-1.el10_2
Red Hat Enterprise Linux 9 unspecified 0:4.13.4-1.el9_8
Red Hat Enterprise Linux 6 unspecified —
Red Hat Enterprise Linux 7 unspecified —
Red Hat Enterprise Linux 8 unspecified —
TIMELINE
Aug 11 Reserved by redhat
Aug 11 Published (CNA: redhat)
Aug 20 RESCORED — CVE-2026-19550 (Red Hat Enterprise Linux 10). CVSS 4.3 → 8.2 (NVD).
Sep 23 PATCH SHIPPED — CVE-2026-19550 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8.
Description
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| August 11, 2026 | Reserved | Reserved by redhat |
| August 11, 2026 | Published | Published (CNA: redhat) |
| August 20, 2026 | RESCORED | RESCORED — CVE-2026-19550 (Red Hat Enterprise Linux 10). CVSS 4.3 → 8.2 (NVD). |
| September 23, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-19550 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:4.13.4-1.el9_8. |
Affected
Affected products and packages — 5 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | 0:4.13.4-1.el10_2 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:4.13.4-1.el9_8 |
| Red Hat | Red Hat Enterprise Linux 6 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-19550 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.