< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-08T16:52:07+05:30

Critical FreeIPA Vulnerability Chain Enables Unauthenticated Admin Credential Creation

A critical vulnerability chain in FreeIPA allows anonymous clients to create reusable administrator credentials by exploiting flaws in Kerberos identity management and 389 Directory Server access controls. The issue affects default installations and requires patching across multiple components including FreeIPA 4.13.4 and 389-ds-base.

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.

FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software.

The

Read original article

*** END OF TRANSMISSION ***