SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18147

HIGH · CVSS 8.1 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page allows unauthenticated remote attackers to inject and execute arbitrary JavaScript code by tricking users into clicking a malicious link. This could enable attackers to manipulate actions within the victim's authenticated session, posing a significant risk of gaining full administrative control, particularly if an IdM administrator is compromised. Organizations using FreeIPA should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18147
Severity
HIGH
CVSS
8.1
EPSS
0.29%
Java

Original NVD Description

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.