Cross-site Scripting (XSS) Affecting ipa-server-common package, versions <0:4.13.4-1.0.1.el10_2


Severity

Recommended
critical

Based on Oracle Linux security rating.

Threat Intelligence

EPSS
0.34% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ORACLE10-IPASERVERCOMMON-20196966
  • published28 Sept 2026
  • disclosed9 Sept 2026

Introduced: 9 Sep 2026

NewCVE-2026-18147  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade Oracle:10 ipa-server-common to version 0:4.13.4-1.0.1.el10_2 or higher.
This issue was patched in ELSA-2026-72279.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ipa-server-common package and not the ipa-server-common package as distributed by Oracle. See How to fix? for Oracle:10 relevant fixed versions and status.

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.

CVSS Base Scores

version 3.1