Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-76578

ipa: freeipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI (critical)
Back to all
CVE

CVE-2026-76578

ipa: freeipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI (critical)

DOCUMENTATION: A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services. 

            STATEMENT: This is a Critical flaw allowing complete, unauthenticated compromise of a FreeIPA/IdM server's administrative privileges. The technique originally disclosed impersonated the literal admin account via a canonical-name collision; a separate prior fix (CVE-2026-13097) now blocks that specific collision but does not address the underlying unauthenticated write access. The attack still succeeds by having the anonymously-created principal added to the administrators group under an attacker-chosen name, reaching the same practical outcome. Exploitation of the original collision-based technique has been independently confirmed by Red Hat against a default, unmodified FreeIPA installation and requires no credentials, user interaction, or prior access, only network reachability to the LDAP service. Any FreeIPA/IdM deployment exposing LDAP to an untrusted network should be considered at immediate risk until patched.

            MITIGATION: Until a fixed package is available, restrict network access to the LDAP service (typically ports 389/636) to trusted hosts only, using firewall rules or network segmentation. Disabling anonymous LDAP binds blocks this specific attack path, though administrators should confirm this does not break other required anonymous-bind functionality in their deployment before applying it.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-
C
H
U
-

Related Resources

No items found.

References

https://access.redhat.com/security/cve/CVE-2026-76578

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00974%
EPSS Percentile
0.60893%
Introduced Version
0
Fix Available
0:4.13.4-1.el9_8,4.13.4-1.el10_2,0:4.13.4-1.0.1.el10_2,0:4.13.4-1.0.1.el9_8,0:4.6.8-5.amzn2.17.6

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading