Skip to content
Red HatCVE-2026-76578

Red Hat FreeIPA: missing authentication

Critical9.8CVE-2026-76578 · Published Sep 7, 2026 · updated Sep 24, 2026

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat GLib2.: link following
Medium5.3Sep 7
Red Hat 389 Directory Server: denial of service
High7.5Sep 7
Red Hat 389 Directory Server: improper authentication
Critical9.8Sep 7
Red Hat 389-ds-base. The Cockpit 389 Console: command injection
High8.4Sep 7
Red Hat: buffer overflow
High7.5Sep 7
Red Hat 389 Directory Server: improper access control
High7.5Sep 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.