Find notable cyber news and cases, enriched with sources, timelines, and signals.

FreeIPA anonymous Kerberos identity privilege escalation (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

FreeIPA faces a critical privilege-escalation chain on default installations after an unauthenticated client can create a Kerberos identity and reach administrators-group privileges. The issue is tied to CVE-2026-76578 and the supporting 389 Directory Server CVE-2026-76560 ownership-check flaw. FreeIPA 4.13.4 fixes the FreeIPA side, and Red Hat reproduced the chain on stock installs. Temporary mitigation is to limit LDAP access and review anonymous bind use.

Timeline

  1. 08.09.2026 14:22 2 articles · 22h ago

    FreeIPA anonymous Kerberos identity privilege escalation (multiple vulnerabilities)

    Initial Disclosure

    An unauthenticated write path in FreeIPA can be chained with 389 Directory Server ownership checks to create a Kerberos identity and escalate into administrators-group access. Red Hat says the FreeIPA side is fixed in 4.13.4 while the directory-server flaw is tracked separately as CVE-2026-76560.

    Show sources