← Terug naar overzicht

A critical vulnerability has been identified in FreeIPA affecting environments where a trust relationship exists between FreeIPA and Active Directory. Authenticated Active Directory users can bypass authentication mechanisms for FreeIPA services including the web portal, SMB server, and LDAP directory. The attack vector involves impersonating a client name within the Ticket Granting Service (TGS) due to FreeIPA's failure to verify Privilege Attribute Certificate (PAC) certificates. Successful exploitation allows privilege escalation within the FreeIPA domain. The vulnerability is tracked as CVE-2026-11861 and is currently awaiting full analysis on NVD. Red Hat has published an advisory and a corresponding Bugzilla report has been filed. Organizations using FreeIPA with Active Directory trust relationships are at elevated risk.

Affected products

  • Active Directory
  • FreeIPA

Related CVE's

  • CVE-2026-11861

Categories

  • Enterprise Applications
  • Identity & Access
  • Network Infrastructure