Tag

#Red Hat

articleCRITICAL 9.8

Critical Authentication Bypass Vulnerability in 389 Directory Server (CVE-2026-18922)

A critical vulnerability (CVE-2026-18922) with a CVSS score of 9.8 has been discovered in the 389 Directory Server, a widely used open-source LDAP server. This flaw allows an attacker to bypass authentication and gain elevated privileges, potentially leading to unauthorized access and control of sensitive directory data. The vulnerability is particularly severe as it can be exploited without any valid credentials. Affected products include various versions of Red Hat Directory Server and Red Hat Enterprise Linux.

1 source
blogHIGH 7.5

Understanding and Defending Against CVE-2026-15565: A Denial of Service Vulnerability in Undertow

CVE-2026-15565 is a high-severity vulnerability in the Undertow web server that allows remote attackers to cause a Denial of Service (DoS) attack without authentication. This vulnerability affects several Red Hat products and has a CVSS score of 7.5. In this analysis, we will delve into the root cause, attack surface, and exploitation mechanics of this vulnerability, as well as provide guidance on detection and defense.

1 source
articleCRITICAL 9.0

Critical Path Traversal Vulnerability in Red Hat Ansible Automation Platform and Satellite (CVE-2026-12701)

A high-severity path traversal vulnerability (CVE-2026-12701, CVSS 9) was discovered in pulpcore, affecting Red Hat Ansible Automation Platform and Satellite. An authenticated administrator can exploit this flaw to write arbitrary files to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation. Immediate patching is recommended.

1 source