A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade freeipa-server | Sep 18, 2026 | Sep 11, 2026 |
| Redhat_linux | — | Upgrade ipa-server-dnsUpgrade ipa-selinux-nfastUpgrade python3-ipaserverUpgrade ipa-debuginfoUpgrade ipa-selinux-lunaUpgrade ipa-client-encrypted-dnsUpgrade ipa-debugsourceUpgrade ipa-serverUpgrade ipa-server-encrypted-dnsUpgrade ipa-commonUpgrade ipa-server-trust-adNo solution existsUpgrade ipa-server-debuginfoUpgrade ipa-client-epnUpgrade ipa-clientUpgrade ipa-client-commonUpgrade python3-ipaclientUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-client-sambaUpgrade python3-ipalibUpgrade ipa-server-commonUpgrade ipa-client-debuginfoUpgrade python3-ipatestsUpgrade ipa-selinux | Aug 24, 2026 | Aug 20, 2026 |
| Rocky_linux | — | Upgrade ipa-debuginfoUpgrade ipa-client-sambaUpgrade ipa-clientUpgrade ipa-server-encrypted-dnsUpgrade ipa-client-debuginfoUpgrade ipa-serverUpgrade ipa-client-encrypted-dnsUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-server-trust-adUpgrade ipa-server-debuginfoUpgrade ipa-client-epnUpgrade ipa-debugsource | Sep 28, 2026 | Sep 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub