FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials Swati KhandelwalSep 08, 2026Vulnerability / Linux A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The FreeIPA project has already fixed its side in version 4.13.4. Red Hat says it reproduced the chain twice on a default installation, most recently on a machine with no access at all. Red…
CVEs: CVE-2026-76578, CVE-2026-76560, CVE-2026-13097, CVE-2026-79678
Original source: thehackernews.com