Vulnerability
Published 2026-09-08
Verified 2026-09-19
FreeIPA flaw chain: anonymous client can mint Kerberos admin credentials (Red Hat)
The Hacker News (8 September 2026) summarises Red Hat guidance that a FreeIPA flaw lets a client that has never logged in create a Kerberos identity of its choosing in the directory and end up in the administrators group. FreeIPA stores identities in 389 Directory Server over LDAP; the attack also needs a second flaw in that database software. Wire abstract does not list CVE IDs or fixed package versions — operators should pull current RHEL/FreeIPA errata from Red Hat rather than inventing patch levels. Primary wire: The Hacker News pending RHSA deep-link. Watchlist relevance: Red Hat / identity plane.
- Product
- FreeIPA / 389 Directory Server (Red Hat identity domain)
- Versions
- See Red Hat errata for FreeIPA and 389-ds; wire does not publish a single fixed NVR
- Exploited in Australia?
- unknown
- Patch to
- Apply Red Hat FreeIPA and 389 Directory Server security updates; audit unexpected Kerberos principals and administrators-group membership; restrict anonymous LDAP binds
Primary: The Hacker News — FreeIPA admin credential chain (8 Sep 2026) · Vendor: Red Hat Security (apply current FreeIPA / 389-ds errata)
