Skip to content

CVE-2026-76578

access.redhat.com September 14, 2026

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.

This is a Critical flaw allowing complete, unauthenticated compromise of a FreeIPA/IdM server's administrative privileges. The technique originally disclosed impersonated the literal admin account via a canonical-name collision; a separate prior fix (CVE-2026-13097) now blocks that specific collision but does not address the underlying unauthenticated write access. The attack still succeeds by having the anonymously-created principal added to the administrators group under an attacker-chosen name, reaching the same practical outcome. Exploitation of the original collision-based technique has been independently confirmed by Red Hat against a default, unmodified FreeIPA installation and requires no credentials, user interaction, or prior access, only network reachability to the LDAP service. Any FreeIPA/IdM deployment exposing LDAP to an untrusted network should be considered at immediate risk until patched.

Until a fixed package is available, restrict network access to the LDAP service (typically ports 389/636) to trusted hosts only, using firewall rules or network segmentation. Disabling anonymous LDAP binds blocks this specific attack path, though administrators should confirm this does not break other required anonymous-bind functionality in their deployment before applying it.

Bugzilla 2519522 : ipa: freeipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI

CWE-306 : Missing Authentication for Critical Function

Common Vulnerability Scoring System (CVSS) Score Details

Info alert: Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications ).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Red Hat CVSS v3 Score Explanation

Independently reproduced twice (most recently from a client with zero prior access) into full, genuine FreeIPA administrator compromise. AV:N/AC:L/PR:N/UI:N: unauthenticated LDAP network client, deterministic on a stock default install, zero credentials, fully attacker-driven. S:U: impact stays within the IPA server's own administrative domain (LDAP+KDC+HTTP/Dogtag are one bundled authority). C:H/I:H/A:H: confirmed real admin LDAP read, real admin-only write/delete (ipa user-add/user-del), and demonstrated ability to disrupt the directory via the same access.

Understanding the Weakness (CWE)

Technical Impact: Gain Privileges or Assume Identity; Varies by Context

Exposing critical functionality essentially provides an attacker with the privilege level of that functionality. The consequences will depend on the associated functionality, but they can range from reading or modifying sensitive data, accessing administrative or other privileged functionality, or possibly even executing arbitrary code.

Red Hat would like to thank Gia Bui (yabeow) (Calif.io) for reporting this issue.

Frequently Asked Questions

"Under investigation" doesn't necessarily mean that the product is affected by this vulnerability. It only means that our Analysis Team is still working on determining whether the product is affected and how it is affected.

The term 'Affected' means that our Analysis team has determined that this product, such as Red Hat Enterprise Linux 8 or OpenShift Container Platform 4, is affected by this vulnerability and a fix may be released to address this issue in the near future. This includes all minor releases of this product unless noted otherwise in the Statement text.

Upgrade to a supported product version that includes a fix for this vulnerability (recommended).

Apply a mitigation (if one exists).

Customers with the Technical Account Manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.

Apply a mitigation (if one exists).

Red Hat Engineering focuses on addressing high-priority issues based on the impact and product lifecycle expectations. Therefore, lower-priority issues will not receive immediate fixes.

Customers with the technical account manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.

Not sure what something means? Check out our Security Glossary .

For clarification or corrections, please Red Hat Product Security .