CVE-2026-18147
largeUnauthenticated DOM XSS in FreeIPA/IdM Web UI password reset page
CVE-2026-18147 is a DOM-based cross-site scripting flaw (CWE-79) in the password reset page of the FreeIPA/Identity Management (IdM) web UI, exploitable by an unauthenticated remote attacker. The attacker triggers it by luring a victim to click a specially crafted link and having the victim complete the password reset flow, at which point attacker-supplied JavaScript executes in the victim's browser. The injected code runs within the victim's authenticated session, letting the attacker perform actions as that user, and could lead to full administrative control of the IdM domain if the victim is an IdM administrator - reflected in the high CVSS 3.1 score of 8.1 (high confidentiality and integrity impact). Any organization running FreeIPA or Red Hat IdM whose users access the web UI password reset page is potentially affected; fixed version information is not included in the available data. There is no evidence of exploitation to date: the flaw is not in CISA KEV, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.
What to do: Apply the FreeIPA upstream and Red Hat IdM security updates referenced in vendor advisories once released, since fixed package versions are not given in the provided data. Until patching, caution users against clicking unsolicited password-reset links, verify the Web UI URL before completing any reset, and restrict Web UI access to trusted networks or VPN. Administrators should also check whether any FreeIPA/IdM web UI instances are reachable by untrusted parties and monitor Red Hat advisories for the patched versions.
| FreeIPA (upstream open-source project) FreeIPA Web UI - password reset page | — |
| Red Hat Identity Management (IdM) web UI (RHEL ipa packages) - password reset page | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.