FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
AdvisoryWindows ALPCWindows Update StackOur summary
Red Hat has disclosed a critical vulnerability chain in FreeIPA, tracked as CVE-2026-76578, which allows unauthenticated clients to create arbitrary Kerberos identities with administrator privileges. This attack exploits a combination of the identity management flaw and a separate issue in 389 Directory Server (CVE-2026-76560), enabling attackers to bypass ownership checks and write privileged entries to the directory database.
The FreeIPA project has addressed this through version 4.13.4, while Red Hat has released patches for various distributions including RHEL and Fedora. Additionally, a second unrelated flaw in FreeIPA, CVE-2026-79678, was identified that allows authenticated users to leak environment variables via an unsafe eval call in the idp-add command.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.