Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-76578Full Admin Takeover in FreeIPA via LDAP Bypass

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.

View on NVD

Analysis

FreeIPA is vulnerable to a pre-authentication bypass that allows an attacker to create administrative Kerberos principals. This results in full compromise of the identity management domain and all integrated Linux services.

Relevant roles

ciberseguridadBackendLinuxCloudKubernetesDocker

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-306

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.

Published: 9/7/2026, 1:20:36 PM
Last modified: 9/7/2026, 1:20:36 PM

References

InicioEventosBlogRecursosCursosEquipo