Thehackernews
Critical FreeIPA Vulnerabilities Allow Unauthenticated Admin Access
Article Content
A critical flaw in FreeIPA, tracked as CVE-2026-76578, allows unauthenticated clients to create Kerberos identities and gain administrative privileges. This vulnerability arises from a misconfigured access control rule in FreeIPA's 389 Directory Server, enabling attackers to exploit it without prior authentication. Red Hat confirmed that this flaw can be exploited on default installations, allowing remote attackers to perform administrative operations. The vulnerability has a CVSS score of 9.8, indicating its critical nature. A related flaw, CVE-2026-13097, was previously addressed but did not fix the underlying unauthenticated write access issue. Red Hat has released a patch for FreeIPA version 4.13.4 to mitigate this risk. Organizations using FreeIPA should restrict LDAP service access and apply the latest patches immediately. The vulnerabilities primarily affect FreeIPA deployments that expose LDAP to untrusted networks.
Key Points: • CVE-2026-76578 allows unauthenticated access to FreeIPA admin privileges. • Exploitation requires no prior authentication or user interaction. • Patches are available, and immediate action is recommended for affected systems.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.