- CVE: CVE-2026-76578
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Red Hat Enterprise Linux 10
- Impact: Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci
- Status: No confirmed exploitation yet
- Action: Update FreeIPA to version 4.13.4
TL;DR
Security researchers discovered FreeIPA CVE-2026-76578, a critical security flaw. This FreeIPA vulnerability carries a CVSS score of 9.8. Unauthenticated attackers can exploit this bug to gain complete administrative privileges over the identity management server.
Why It Matters
FreeIPA allows Linux administrators to centrally manage identity, authentication, and access control. Consequently, a compromised FreeIPA server hands attackers the keys to the entire Linux domain. Red Hat independently confirmed the exploitation of this technique against a default installation. Furthermore, the attack requires no credentials, no user interaction, and no prior access. Any deployment exposing the LDAP service to an untrusted network faces immediate risk of complete takeover.
How the Attack Works
The FreeIPA CVE-2026-76578 exploit abuses the self-managed OTP token access control instruction. This ACI does not require authentication. Additionally, it fails to restrict which attributes attackers can add alongside the token entry. An unauthenticated LDAP client exploits this gap, along with a related directory server flaw. The attacker creates an arbitrary, attacker-controlled Kerberos principal. Then, they add this new principal directly to the administrators group. A previous patch for CVE-2026-13097 blocked a specific canonical-name collision. However, the underlying unauthenticated write access remained open. Now, attackers succeed by placing their anonymously-created principal into the admin group under a chosen name.
Affected Versions
The FreeIPA vulnerability impacts default, unmodified FreeIPA and Red Hat Identity Management installations. Deployments that integrate with Active Directory via cross-realm Kerberos trust also remain at risk.
Patch or Mitigation Steps
Administrators should monitor the official security advisory for the release of fixed packages. Until a patch becomes available, you must restrict network access to the LDAP service immediately. Use firewall rules to limit ports 389 and 636 to trusted hosts only. Disabling anonymous LDAP binds blocks this specific attack path. However, administrators must confirm that disabling anonymous binds does not break other required functionality before applying this change.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!