Reach an IPA master or replica's LDAP service without credentials→↓Use an anonymous bind to add an OTP-shaped entry with empty owner fields and attacker-chosen Kerberos principal attributes→↓The 389 Directory Server SELFDN check accepts the empty fields as the anonymous client's own identity→↓FreeIPA's permissive ADD ACI admits the extra principal and group-related attributes→↓Authenticate as the attacker-controlled principal with genuine FreeIPA administrator-group authority
Why this matters
The path replaces an identity server's administrative trust root from outside the domain.
Detail and 3 sources
Required access
Unauthenticated network reachability to the FreeIPA server's LDAP service on TCP/389 or TCP/636
Affected versions
FreeIPA server releases before 4.13.4 that contain the vulnerable self-managed-token ACI and use an affected 389 Directory Server, Red Hat IdM packages still listed as affected or under investigation on 2026-09-08
Proof of concept
Demonstrated by the researcher
The primitive composes FreeIPA's permissive ADD ACI with 389 Directory Server's treatment of an anonymous empty bind DN as matching empty owner fields.
Red Hat reproduced full compromise twice, including from a zero-access client against a stock installation.
FreeIPA 4.13.4 hardens the vulnerable ACI composition.
Evidence
Red Hat independently reproduced full administrator compromise twice, including on a stock installation from a zero-access clientFreeIPA 4.13.4 documents the vulnerable ACI composition and the shipped hardening
Preconditions
access:network:internet
reachable from the public internet
interaction:none
no user action required
Patch reality
Reaches end-of-life hardware
No
The first two fields are effectively not-applicable questions for this server-side access-control fix, so they are recorded as unknown rather than forcing a misleading definite value.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.