Multiple security vulnerabilities affecting FreeIPA versions The FreeIPA vulnerability impacts default, unmodified FreeIPA and Red Hat Identity Management installations have been identified in Red Hat Enterprise Linux 10 and default, unmodified FreeIPA installations. The overall risk/impact is critical, as unauthenticated attackers can exploit these flaws to gain complete administrative privileges over the identity management server.
CVE-2026-76578 (CVSS 9.8 — Critical): A critical security flaw in FreeIPA allows an unauthenticated LDAP client to obtain administrator credentials via the self-managed-token ACI. This vulnerability carries a CVSS score of 9.8 and requires no credentials, user interaction, or prior access.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting FreeIPA versions The FreeIPA vulnerability impacts default, unmodified FreeIPA and Red Hat Identity Management installations have been identified in Red Hat Enterprise Linux 10 and default, unmodified FreeIPA installations. The overall risk/impact is critical, as unauthenticated attackers can exploit these flaws to gain complete administrative privileges over the identity management server.
CVE-2026-76578 (CVSS 9.8 — Critical): A critical security flaw in FreeIPA allows an unauthenticated LDAP client to obtain administrator credentials via the self-managed-token ACI. This vulnerability carries a CVSS score of 9.8 and requires no credentials, user interaction, or prior access.[emaillocker id="1283"]
CVE-2026-13097: A related directory server flaw was previously patched, but the underlying unauthenticated write access remained open. Attackers can exploit this gap to add an arbitrary, attacker-controlled Kerberos principal directly to the administrators group.
We recommend you to update FreeIPA to version 4.13.4.
The following reports contain further technical details:
[/emaillocker]