CVE-2026-18147
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- CWE
- CWE-79
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Weakness type
Related vulnerabilities
- CVE-2026-81635 — A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an...
- CVE-2026-0308 — PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
- CVE-2026-85645 — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting
- CVE-2026-76562 — Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting via 'sbm_description' Parameter
- CVE-2026-4657 — Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via control_selectors Meta Field
- CVE-2026-15820 — Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Module 'attributes' Setting
- CVE-2026-15796 — Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting
- CVE-2026-87870 — Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Parameters