FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
- ID
- 22330
- Status
- summarized
- Published
- 08 Sep 2026, 7:22 PM
- Fetched
- 08 Sep 2026, 8:05 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 08 Sep 2026, 8:10 PM
- Tags
- Audience
- developers
What happened
A chain of two flaws lets an anonymous, unauthenticated client create reusable Kerberos administrator credentials on a default FreeIPA installation. The first flaw (CVE-2026-76578, CVSS 9.8) is in FreeIPA's shipped ACI rule for self-managed OTP tokens, which doesn't require login; the second (CVE-2026-76560, CVSS 7.5) is in 389 Directory Server's ownership check, which matches an empty client name against an empty stored value. FreeIPA fixed its side in version 4.13.4; the 389-ds side remains the access-control engine defect Red Hat reproduced independently.
Why it matters
If you run FreeIPA or Red Hat Identity Management on version < 4.13.4, patch now—an unauthenticated attacker on a default install can escalate to domain administrator. If you don't run FreeIPA, this has no direct impact on your stack.
Discussion angle
The design lesson: an ACI rule that doesn't require authentication combined with a string-comparison ownership check that treats 'nobody' as a valid owner—how default-shipped rules can turn a moderate flaw into a critical chain.