FreeIPA anonymous Kerberos identity privilege escalation (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
FreeIPA faces a critical privilege-escalation chain on default installations after an unauthenticated client can create a Kerberos identity and reach administrators-group privileges. The issue is tied to CVE-2026-76578 and the supporting 389 Directory Server CVE-2026-76560 ownership-check flaw. FreeIPA 4.13.4 fixes the FreeIPA side, and Red Hat reproduced the chain on stock installs. Temporary mitigation is to limit LDAP access and review anonymous bind use.
Timeline
-
08.09.2026 14:22 2 articles · 22h ago
FreeIPA anonymous Kerberos identity privilege escalation (multiple vulnerabilities)
Initial DisclosureAn unauthenticated write path in FreeIPA can be chained with 389 Directory Server ownership checks to create a Kerberos identity and escalate into administrators-group access. Red Hat says the FreeIPA side is fixed in 4.13.4 while the directory-server flaw is tracked separately as CVE-2026-76560.
Show sources
- FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials — thehackernews.com — 08.09.2026 14:22
- FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials — thehackernews.com — 08.09.2026 14:22