CVE Tools

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

The Hacker NewsBy The Hacker News

AdvisoryWindows ALPCWindows Update Stack

Our summary

Red Hat has disclosed a critical vulnerability chain in FreeIPA, tracked as CVE-2026-76578, which allows unauthenticated clients to create arbitrary Kerberos identities with administrator privileges. This attack exploits a combination of the identity management flaw and a separate issue in 389 Directory Server (CVE-2026-76560), enabling attackers to bypass ownership checks and write privileged entries to the directory database.

The FreeIPA project has addressed this through version 4.13.4, while Red Hat has released patches for various distributions including RHEL and Fedora. Additionally, a second unrelated flaw in FreeIPA, CVE-2026-79678, was identified that allows authenticated users to leak environment variables via an unsafe eval call in the idp-add command.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store