← Back to overview

A critical vulnerability was discovered in FreeIPA where the self-managed OTP token Access Control Instruction (ACI) neither requires authentication nor restricts which attributes may be added alongside a token entry. An unauthenticated LDAP client can exploit this flaw, in combination with a related directory server ACI evaluation vulnerability, to create an attacker-controlled Kerberos principal and insert it into the FreeIPA administrators group. This grants the remote, unauthenticated attacker full FreeIPA administrator-group membership, enabling administrative operations against the directory. On SID-enabled deployments, the impact extends to other Identity Management (IdM) services. The flaw represents a severe authentication bypass leading to complete privilege escalation. It is tracked under CVE-2026-76578 and referenced in Red Hat security advisories and Bugzilla.

Affected products

  • FreeIPA
  • Red Hat Identity Management (IdM)

Related CVE's

  • CVE-2026-76578

Categories

  • Enterprise Applications
  • Identity & Access
  • Zero-Day Vulnerabilities