CVE-2026-76578

9.8

Red Hat · FreeIPA

An unauthenticated vulnerability in FreeIPA allows attackers to create arbitrary Kerberos principals and grant themselves administrative privileges via the self-managed OTP token ACI.

Executive summary

A critical vulnerability in FreeIPA enables unauthenticated remote attackers to gain full administrative control over Identity Management services.

Vulnerability

The vulnerability stems from a flaw in the self-managed OTP token access control instruction, which lacks authentication requirements and fails to restrict attributes added to the token entry. An unauthenticated attacker can leverage this to create unauthorized Kerberos principals and inject them into the administrator group.

Business impact

This vulnerability carries a CVSS score of 9.8, reflecting its critical severity. Successful exploitation allows a remote, unauthenticated attacker to achieve complete administrative compromise of the directory server and associated IdM services. This leads to total loss of confidentiality, integrity, and availability for the identity infrastructure, potentially enabling lateral movement across the entire enterprise network.

Remediation

Immediate Action: Update all affected FreeIPA and Red Hat Identity Management installations to version 4.13.4 immediately.

Proactive Monitoring: Monitor LDAP access logs for unusual administrative group modifications or the creation of suspicious Kerberos principals.

Compensating Controls: If patching is delayed, restrict network access to the FreeIPA service to known, trusted management segments to limit exposure to unauthenticated requests.

Exploitation status

Public Exploit Available: Yes — confirmed by Red Hat independently.

Analyst recommendation

Given the critical nature of this flaw and the confirmation of active exploitation in the wild, organizations must prioritize patching their identity management infrastructure. Failure to update to version 4.13.4 leaves the environment vulnerable to total administrative takeover by unauthenticated remote actors.

More Red Hat CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief critical section

Sources

Originally found and disclosed by Red Hat would like to thank Gia Bui (yabeow) (Calif.io) for reporting this issue., per the CVE Program record.