← Terug naar overzicht

A privilege escalation vulnerability (CVE-2026-13097) was discovered in FreeIPA affecting the 389-ds directory server. The flaw lies in the uniqueness constraint enforced on Kerberos principal name attributes, which fails to account for equivalent representations of the same principal name. An attacker with sufficient LDAP write privileges can exploit this to create a service principal that impersonates an existing privileged one. This allows unauthorized acquisition of Kerberos service tickets for sensitive services. The potential impact is severe, including full domain compromise. The vulnerability is currently awaiting analysis on the NVD. Red Hat has acknowledged the issue and a corresponding Bugzilla report has been filed.

Affected products

  • 389-ds Directory Server
  • FreeIPA

Related CVE's

  • CVE-2026-13097

Categories

  • Enterprise Applications
  • Identity & Access