securityonline.info 7 Sept 2026, 16:24 UTC

Critical FreeIPA Flaw Lets Attackers Seize Identity Servers

Critical FreeIPA Flaw Lets Attackers Seize Identity Servers
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CVE- 2026-76578 is a critical vulnerability in FreeIPA with a CVSS score of 9.8. The issue affects Red Hat Enterprise Linux 10 and related FreeIPA deployments, with unauthenticated LDAP access potentially granting complete administrative privileges over the identity management server. The advisory notes that there is no confirmed exploitation at the time of reporting, but the risk is severe for unpatched systems exposed to untrusted networks. The recommended action is to update FreeIPA to version 4.13.4.

How the attack works, as described in the report, centres on the self-managed OTP token ACI. An unauthenticated LDAP client can abuse this token control instruction and, due to insufficient restriction on which attributes can be added with the token entry, create an attacker-controlled Kerberos principal. This principal can then be added directly to the administrators group, effectively conceding full control of the FreeIPA server.

The report mentions a prior patch for CVE-2026-13097 addressing a canonical-name collision, but notes that unauthenticated write access remained open and is now exploitable to place an anonymous principal into the admin group under a chosen name.

Affected environments include default, unmodified FreeIPA installations and Red Hat Identity Management, with additional risk for deployments that integrate with Active Directory via cross-realm Kerberos trust. Until patches are available, the guidance is to restrict access to LDAP (ports 389 and 636) via firewalls and to disable anonymous binds, subject to functional compatibility with legitimate services. The official fix is released in FreeIPA 4.13.4. 7 September 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline