A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade freeipa-server | Sep 18, 2026 | Sep 11, 2026 |
| Redhat_linux | — | Upgrade ipa-debuginfoUpgrade ipa-selinuxUpgrade ipa-serverUpgrade ipa-clientUpgrade ipa-client-epnUpgrade ipa-commonUpgrade ipa-client-encrypted-dnsUpgrade python3-ipaclientUpgrade python3-ipaserverUpgrade ipa-client-sambaUpgrade python3-ipatestsUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-debugsourceUpgrade python3-ipalibUpgrade ipa-server-trust-adUpgrade ipa-server-debuginfoNo solution existsUpgrade ipa-server-dnsUpgrade ipa-server-encrypted-dnsUpgrade ipa-client-commonUpgrade ipa-selinux-nfastUpgrade ipa-client-debuginfoUpgrade ipa-selinux-lunaUpgrade ipa-server-common | Sep 9, 2026 | Sep 7, 2026 |
| Rocky_linux | — | Upgrade ipa-server-debuginfoUpgrade ipa-client-debuginfoUpgrade ipa-debugsourceUpgrade ipa-debuginfoUpgrade ipa-server-encrypted-dnsUpgrade ipa-server-trust-adUpgrade ipa-client-encrypted-dnsUpgrade ipa-clientUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-serverUpgrade ipa-client-sambaUpgrade ipa-client-epn | Sep 28, 2026 | Sep 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub