Ethical Hacking News
A critical vulnerability has been discovered in FreeIPA, a widely used identity management system in Linux domains. The vulnerability, identified as CVE-2026-76578, allows anonymous clients to create reusable administrator credentials, effectively granting unauthorized access to the system. This vulnerability can be exploited by attackers to gain access to sensitive data and perform malicious activities on the system. System administrators are advised to take necessary precautions to mitigate the risk of this vulnerability, including restricting access to the LDAP service and running the idp-add command with caution.
FreeIPA, a widely used identity management system in Linux domains, contains a critical flaw that allows anonymous clients to create reusable administrator credentials.The flaw, identified as CVE-2026-76578, has a CVSS score of 9.8 and was rated critical by Red Hat.Two flaws were discovered: one allowing a client to create a Kerberos identity of its own choosing, and another related to the 389 Directory Server software.The combined effect of the flaws allows an attacker to create a new identity with administrator credentials, gaining unauthorized access to the system.Red Hat has acknowledged the vulnerability and released a patch, but it has not yet been widely adopted.A second vulnerability, CVE-2026-79678, has also been disclosed in the 389 Directory Server software.To mitigate the risk, system administrators should restrict access to the LDAP service, turn off anonymous LDAP binds, and apply patches.
FreeIPA, a widely used identity management system in Linux domains, has been found to contain a critical flaw that allows anonymous clients to create reusable administrator credentials. This vulnerability, identified as CVE-2026-76578, has been rated critical by Red Hat, with a CVSS score of 9.8. The flaw was discovered by Swati Khandelwal, a researcher who identified a chain of vulnerabilities in FreeIPA that can be exploited by attackers.
According to Red Hat, the first flaw in FreeIPA allows a client to create a Kerberos identity of its own choosing in the directory, effectively granting the client access to the administrators group. This is made possible by a flawed access control rule in the system, which does not require the client to have logged in and can be exploited by an attacker to create a new identity.
The second flaw in FreeIPA is related to the 389 Directory Server software, which is used to store and manage identities in the system. This flaw allows an attacker to create a new identity with empty ownership fields, which can then be used to create a new Kerberos identity. This is made possible by a flawed rule in the Directory Server software that allows an attacker to write to the directory with empty ownership fields.
The combined effect of these two flaws allows an attacker to create a new identity with administrator credentials, effectively gaining unauthorized access to the system. This vulnerability can be exploited by attackers to gain access to sensitive data and perform malicious activities on the system.
Red Hat has acknowledged this vulnerability and has released a patch for the affected systems. However, the patch has not yet been widely adopted, and the vulnerability remains a significant concern for system administrators and security professionals.
In addition to the FreeIPA vulnerability, Red Hat has also disclosed a second vulnerability in the 389 Directory Server software, CVE-2026-79678. This vulnerability allows an attacker to read the server process's environment variables one at a time, which can potentially be used to obtain sensitive information.
The exploitation of these vulnerabilities is not limited to FreeIPA and 389 Directory Server software. According to Red Hat, an attacker can also use the vulnerabilities to obtain a Kerberos ticket containing authorization data, which can be used to extend access to the server's HTTP and Dogtag services.
To mitigate the risk of this vulnerability, system administrators are advised to take several precautions. First, they should restrict access to the LDAP service to hosts they trust, using firewall rules or network segmentation. Second, they should turn off anonymous LDAP binds, which can block this particular path. However, they should first check that nothing else in their deployment needs these binds.
For the idp-add flaw, there is no such option, and a fixed package is required. System administrators are advised to run the idp-add command with caution and verify that the password set at first boot is no longer present in the running process environment.
The published material leaves two questions unanswered. First, it is unclear whether 389-ds updates, on their own, stop the FreeIPA attack on a server whose ipa packages are still outdated. Second, it is unclear whether applying a fix removes an identity created by an attacker beforehand, and what an administrator should look for to find out.
In conclusion, the FreeIPA flaw chain is a critical vulnerability that affects multiple systems, including Linux domains. It is essential for system administrators and security professionals to be aware of this vulnerability and take necessary precautions to mitigate the risk. By following the recommended precautions and keeping their systems up to date with the latest patches, they can help prevent the exploitation of this vulnerability.
Related Information:
https://www.ethicalhackingnews.com/articles/FreeIPA-Flaw-Chain-Exposed-A-Grave-Vulnerability-Affecting-Multiple-Systems-ehn.shtml
https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
https://nvd.nist.gov/vuln/detail/CVE-2026-76578
https://www.cvedetails.com/cve/CVE-2026-76578/
https://nvd.nist.gov/vuln/detail/CVE-2026-79678
https://www.cvedetails.com/cve/CVE-2026-79678/
Published: Tue Sep 8 06:48:26 2026 by llama3.2 3B Q4_K_M