Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities in FreeIPA Allow Unauthorized Access

Critical Vulnerabilities in FreeIPA Allow Unauthorized Access

Posted on September 8, 2026 By CWS

Security researchers have identified a serious vulnerability within FreeIPA, a leading identity management system, that allows unauthorized clients to gain administrative credentials. Red Hat has confirmed and detailed the flaw, which involves creating a Kerberos identity without prior login, subsequently allowing access to administrative privileges.

Understanding the FreeIPA Flaw

FreeIPA, utilized to manage access across Linux domains, relies on a 389 Directory Server database. The vulnerability arises from a flaw in FreeIPA version 4.13.4, which has since been patched. This exploit requires a secondary weakness in the directory server’s software, specifically CVE-2026-76578, which Red Hat rates as critical with a CVSS score of 9.8.

Red Hat’s investigation reproduced the exploit on default installations, demonstrating the vulnerability’s severity. This security issue also affects their Identity Management product, known as ipa, which is shipped with FreeIPA.

Technical Details of the Exploit

The exploit leverages an access control rule in FreeIPA that allows users to manage their own one-time-password tokens without authentication. The associated flaw in the 389 Directory Server allows an anonymous client to create an identity with blank ownership fields, thereby bypassing authentication checks.

This issue is cataloged under CVE-2026-76560 and is rated at 7.5. While Red Hat Directory Server typically does not use such rules by default, FreeIPA’s default configuration does, enabling this exploit in untouched installations.

Additional FreeIPA Vulnerabilities

Alongside the primary vulnerability, Red Hat disclosed another flaw, CVE-2026-79678, unrelated to the main exploit chain but still significant. This flaw, scoring 8.1, involves the idp-add command, which improperly processes user-supplied inputs before performing necessary permission checks.

Although the vulnerability does not allow code execution, it could enable attackers to read server environment variables or exhaust server memory resources. The impact varies based on the installation method, notably affecting environments where passwords are stored as environment variables.

Mitigation and Future Actions

To mitigate these vulnerabilities, administrators are advised to apply patches released by FreeIPA and Red Hat promptly. Until patched versions are available, restricting access to LDAP services through network measures can alleviate the risk. For the idp-add flaw, no workaround exists, necessitating updates to the affected packages.

While Red Hat has provided guidance, questions remain regarding whether the current patches remove previously created unauthorized identities, leaving administrators to monitor for any anomalies in their systems. The absence of detection rules complicates efforts to identify potential breaches.

Overall, these vulnerabilities highlight the critical need for vigilant patch management and comprehensive security practices within Linux domains.

The Hacker News Tags:389 Directory Server, access control, administrator credentials, CVE, Cybersecurity, FreeIPA, identity management, Kerberos, LDAP, Linux, Patch, Red Hat, Security, server security, Vulnerabilities

Post navigation

Previous Post: U.S. Offers $10M for Iranian Cyber Chief Behind Attacks
Next Post: MikroTik Urges Immediate Updates for Critical RouterOS Flaws

Related Posts

China-Linked Cyber Threats Target Southeast Asian Government China-Linked Cyber Threats Target Southeast Asian Government The Hacker News
PhantomEnigma Hijacks Government Sites for Malware PhantomEnigma Hijacks Government Sites for Malware The Hacker News
AI-Based Phishing Scheme Targets Apple Device Owners AI-Based Phishing Scheme Targets Apple Device Owners The Hacker News
Deepfake Defense in the Age of AI Deepfake Defense in the Age of AI The Hacker News
Chrome DevTools Enables Session Hijacking in Windows Chrome DevTools Enables Session Hijacking in Windows The Hacker News
Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojan Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojan The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Bots Vulnerable to Security Breaches via Phishing
  • Urgent Fix for Critical Zero-Day in N-central Released
  • Panzer Ransomware Impacting Italian Tech and Manufacturing
  • MikroTik Urges Immediate Updates for Critical RouterOS Flaws
  • Critical Vulnerabilities in FreeIPA Allow Unauthorized Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Bots Vulnerable to Security Breaches via Phishing
  • Urgent Fix for Critical Zero-Day in N-central Released
  • Panzer Ransomware Impacting Italian Tech and Manufacturing
  • MikroTik Urges Immediate Updates for Critical RouterOS Flaws
  • Critical Vulnerabilities in FreeIPA Allow Unauthorized Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark