Skip to content

FreeIPA 4.13.3

www.freeipa.org September 8, 2026

It can be downloaded from . Builds for Fedora distributions will be available from the official repository soon.

Highlights in 4.13.3 #

CVE-2026-11861: FreeIPA: Obtaining TGS with impersonating cname through trust relationships #

When a trust relationship is configured between FreeIPA and Active Directory, under certain conditions Active Directory users can bypass authentication for FreeIPA services, including the Web UI/IPA API, SMB services, and LDAP directory. This is possible by impersonating an client name on Active Directory side in the Ticket Granting Service (TGS) due to FreeIPA application services not verifying Privilege Attribute Certificate (PAC) content. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.

The attack requires a cross-realm trust to be configured between FreeIPA and Active Directory, the attacker must already hold a valid Active Directory account, and the impersonation technique depends on the ability to register a duplicate or conflicting Service Principal Name (SPN) in the Active Directory forest. Microsoft addressed this prerequisite by enforcing SPN and UPN uniqueness constraints on Windows Server 2012 R2 domain controllers with MSKB-3070083 applied, and by default on Windows 11 version 22H2 and later. In environments where the Active Directory domain controllers are patched and running a supported functional level, the attack path is blocked on the Windows side. Only deployments trusting an outdated or unpatched Active Directory environment remain realistically at risk, making this primarily a theoretical concern in modern, maintained environments

Reported by Vladislav Plyatsok (rd01f)

CVE-2026-13097: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore #

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.

Reported by Vladislav Plyatsok (rd01f)

CVE-2026-73196: FreeIPA: Authenticated DoS in otptoken-add via unbounded OTP key decoding/re-encoding #

A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service.

CVE-2026-73197: FreeIPA: Unauthenticated DoS in /ipa/migration/migration.py via Unbounded Request Body Read #

A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the /ipa/migration/migration.py endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.

CVE-2026-73198: FreeIPA: Unauthenticated DoS in /ipa/i18n_messages via Unbounded Request Body Read #

A remote, unauthenticated attacker can exploit a vulnerability in the /ipa/i18n_messages endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.

CVE-2026-73199: FreeIPA: NULL Pointer Dereference in ipa-enrollment Extended Operation ( JOIN_OID ) via Missing Request Value #

A flaw was found in the ipa-enrollment SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the JOIN_OID in the ipa-enrollment extended operation, an attacker can trigger a server crash, potentially causing a denial of service.

The trust-fetch-domains command, used to refresh Active Directory trust topology, is gated only by the read-level ACI on the trust object ( System: Read Trust Information , granted to any authenticated IPA user by default) rather than a trust-administration-level permission. Any authenticated, non-privileged IPA user can therefore invoke ipa trust-fetch-domains , which calls a root-owned oddjobd/D-Bus helper. This may lead to DoS abuse and potential spoofing of trust related topology information.

DNA config change to avoid 2 minutes delay during install

DNA config change to avoid 2 minutes delay during install

FreeIPA 4.13.3 is a stabilization release for the features delivered as a part of 4.13 version series.

There are more than 10 bug-fixes since FreeIPA 4.13.2 release. Details of the bug-fixes can be seen in the list of resolved tickets below.

Upgrade instructions are available on the Upgrade page.

Please provide , bugs and other feedback via the freeipa-users mailing list ( ) or #freeipa channel on libera.chat.

Detailed Changelog since 4.13.2 #

Alexander Bokovoy (9) #

CVE-2026-19550: trust: require write access to refresh trust domains commit

CVE-2026-19550: trust: require write access to refresh trust domains commit

ipatests: add integration tests for krbPrincipalMatch matching rule commit

ipatests: add integration tests for krbPrincipalMatch matching rule commit

Migrate kerberos uniqueness to krbPrincipalMatch on upgrade commit

Migrate kerberos uniqueness to krbPrincipalMatch on upgrade commit

Use krbPrincipalMatch for Kerberos uniqueness enforcement commit

Use krbPrincipalMatch for Kerberos uniqueness enforcement commit

Add Kerberos principal matching rule plugin for 389-ds commit

Add Kerberos principal matching rule plugin for 389-ds commit

Fix LOG_ALERT macro redefinition warning in slapi plugins commit

Fix LOG_ALERT macro redefinition warning in slapi plugins commit

pylint_plugins: fix fake_class() for astroid 4.x commit

pylint_plugins: fix fake_class() for astroid 4.x commit

dna plugin: use global configuration for replica communication commit

dna plugin: use global configuration for replica communication commit

ipa-adtrust-install: remove NetBIOS ports requirement from the text commit #10019

ipa-adtrust-install: remove NetBIOS ports requirement from the text commit #10019

Fix unauthenticated DoS in migration endpoint commit

Fix unauthenticated DoS in migration endpoint commit

Fix unauthenticated DoS in otptoken-add endpoint commit

Fix unauthenticated DoS in otptoken-add endpoint commit

Update modern WebUI to version 0.2.1 commit

Update modern WebUI to version 0.2.1 commit

Update webui to version 0.2.0

Update webui to version 0.2.0

Limit maximum request size for i18n commit

Limit maximum request size for i18n commit

ipatests: Add ipa-getcert request tests for FILE storage commit

ipatests: Add ipa-getcert request tests for FILE storage commit

spec: preserve permissions and ownership of sshd_config in trigger commit #10015

spec: preserve permissions and ownership of sshd_config in trigger commit #10015

Florence Blanc-Renaud (13) #

join extop: return PROTOCOL ERROR if the payload is missing commit

join extop: return PROTOCOL ERROR if the payload is missing commit

ipa-migrate: require Replication Administrator privilege commit #10026

ipa-migrate: require Replication Administrator privilege commit #10026

ipa-otptoken-import: request a MAC if a MAC method is specified commit #10031

ipa-otptoken-import: request a MAC if a MAC method is specified commit #10031

ipa-epn: fix transposed uid/gid and fail closed on drop_privileges() commit #10030

ipa-epn: fix transposed uid/gid and fail closed on drop_privileges() commit #10030

ipa env: support only simple * wildcard commit #10028

ipa env: support only simple * wildcard commit #10028

host-mod: also guard userpassword when delivered via –setattr commit #10027

host-mod: also guard userpassword when delivered via –setattr commit #10027

ipa-otptoken-import: harden lxml parser against XXE commit #10025

ipa-otptoken-import: harden lxml parser against XXE commit #10025

Spec file: bump samba version commit

Spec file: bump samba version commit

HTTPd configuration: set RequestReadTimeout commit #10024

HTTPd configuration: set RequestReadTimeout commit #10024

ipatests: override uninstall in TestHSMcertFix commit #10021

ipatests: override uninstall in TestHSMcertFix commit #10021

ipatests: add xfail depending on softhsm version commit #9920

ipatests: add xfail depending on softhsm version commit #9920

ipatests: add xfail for NTLM authentication tests commit #9999

ipatests: add xfail for NTLM authentication tests commit #9999

webui tests: add xfail for known issues commit #9928

webui tests: add xfail for known issues commit #9928

ipa-lockout: fix ineffective change of krbLoginFailedCount on concurrent udpate commit

ipa-lockout: fix ineffective change of krbLoginFailedCount on concurrent udpate commit

ipa-kdb: Add cross-realm trust PAC content validation commit

ipa-kdb: Add cross-realm trust PAC content validation commit

servicedelegation: Use Principal parameter type for member principals commit

servicedelegation: Use Principal parameter type for member principals commit

Fix LDAP filter injection in S4U2Proxy delegation ACL lookup commit

Fix LDAP filter injection in S4U2Proxy delegation ACL lookup commit

xfail the sudo SSSD offline/caching tests commit

xfail the sudo SSSD offline/caching tests commit

Shalini Khandelwal (1) #

ipatests: Add test for replica CA with external certs commit

ipatests: Add test for replica CA with external certs commit

ipatests: Open NFS firewall port in test_nfs.py commit #10014

ipatests: Open NFS firewall port in test_nfs.py commit #10014