Skip to finding
§
High
Privilege escalation
Confirmed
CVE-2026-76578

An unauthenticated LDAP client can mint a genuine FreeIPA administrator on a stock server.

Anonymous LDAP access to an IPA master or replica is sufficient.

Affects

FreeIPA and Red Hat Identity Management servers, which centrally manage Linux identities, Kerberos credentials, access policy and related services.

What it enables

Unauthenticated FreeIPA administrator-group membership

Reach an IPA master or replica's LDAP service without credentials→↓Use an anonymous bind to add an OTP-shaped entry with empty owner fields and attacker-chosen Kerberos principal attributes→↓The 389 Directory Server SELFDN check accepts the empty fields as the anonymous client's own identity→↓FreeIPA's permissive ADD ACI admits the extra principal and group-related attributes→↓Authenticate as the attacker-controlled principal with genuine FreeIPA administrator-group authority
Why this matters

The path replaces an identity server's administrative trust root from outside the domain.

Detail and 3 sources
Required access

Unauthenticated network reachability to the FreeIPA server's LDAP service on TCP/389 or TCP/636

Affected versions

FreeIPA server releases before 4.13.4 that contain the vulnerable self-managed-token ACI and use an affected 389 Directory Server, Red Hat IdM packages still listed as affected or under investigation on 2026-09-08

Proof of concept

Demonstrated by the researcher

The primitive composes FreeIPA's permissive ADD ACI with 389 Directory Server's treatment of an anonymous empty bind DN as matching empty owner fields.

Red Hat reproduced full compromise twice, including from a zero-access client against a stock installation.

FreeIPA 4.13.4 hardens the vulnerable ACI composition.

Evidence
Red Hat independently reproduced full administrator compromise twice, including on a stock installation from a zero-access clientFreeIPA 4.13.4 documents the vulnerable ACI composition and the shipped hardening
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 8, 2026