AI Weekly Malaysia

Back to items Summaries

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

ID
22330
Status
summarized
Published
08 Sep 2026, 7:22 PM
Fetched
08 Sep 2026, 8:05 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
08 Sep 2026, 8:10 PM
Tags
Audience
developers

What happened

A chain of two flaws lets an anonymous, unauthenticated client create reusable Kerberos administrator credentials on a default FreeIPA installation. The first flaw (CVE-2026-76578, CVSS 9.8) is in FreeIPA's shipped ACI rule for self-managed OTP tokens, which doesn't require login; the second (CVE-2026-76560, CVSS 7.5) is in 389 Directory Server's ownership check, which matches an empty client name against an empty stored value. FreeIPA fixed its side in version 4.13.4; the 389-ds side remains the access-control engine defect Red Hat reproduced independently.

Why it matters

If you run FreeIPA or Red Hat Identity Management on version < 4.13.4, patch now—an unauthenticated attacker on a default install can escalate to domain administrator. If you don't run FreeIPA, this has no direct impact on your stack.

Discussion angle

The design lesson: an ACI rule that doesn't require authentication combined with a string-comparison ownership check that treats 'nobody' as a valid owner—how default-shipped rules can turn a moderate flaw into a critical chain.

Top