Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
6.5
CVE-2026-73199EXPLOITED
red hat · red hat enterprise linux

Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value

Description

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

References

  • https://access.redhat.com/security/cve/CVE-2026-73199(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2471741(issue-tracking, x_refsource_REDHAT)

Related News (1 articles)

Tier C
VulDB3d ago
CVE-2026-73199 | Red Hat Enterprise Linux ipa-enrollment null pointer dereference
→ No new info (linked only)
CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-476
PublishedAug 20, 2026
Last enriched3d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score23
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-13595EXP
Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
Trending: 36
NONECVE-2026-18917EXP
Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow
Trending: 35
NONECVE-2026-17523EXP
Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges
Trending: 33
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 26
NONECVE-2026-77176
Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 20, 2026
Actively Exploited
Aug 20, 2026
Exploit Available
Aug 20, 2026
Discovered by ZDM
Aug 20, 2026