Vulnerability
Published 2026-09-08
Verified 2026-09-19

FreeIPA flaw chain: anonymous client can mint Kerberos admin credentials (Red Hat)

The Hacker News (8 September 2026) summarises Red Hat guidance that a FreeIPA flaw lets a client that has never logged in create a Kerberos identity of its choosing in the directory and end up in the administrators group. FreeIPA stores identities in 389 Directory Server over LDAP; the attack also needs a second flaw in that database software. Wire abstract does not list CVE IDs or fixed package versions — operators should pull current RHEL/FreeIPA errata from Red Hat rather than inventing patch levels. Primary wire: The Hacker News pending RHSA deep-link. Watchlist relevance: Red Hat / identity plane.

Product
FreeIPA / 389 Directory Server (Red Hat identity domain)
Versions
See Red Hat errata for FreeIPA and 389-ds; wire does not publish a single fixed NVR
Exploited in Australia?
unknown
Patch to
Apply Red Hat FreeIPA and 389 Directory Server security updates; audit unexpected Kerberos principals and administrators-group membership; restrict anonymous LDAP binds

Primary: The Hacker News — FreeIPA admin credential chain (8 Sep 2026) · Vendor: Red Hat Security (apply current FreeIPA / 389-ds errata)

vulnerabilities identity cloud