FreeIPA Patch Leaves a Directory Backdoor Question

Red Hat says FreeIPA CVE-2026-76578, chained with a 389 Directory Server flaw, lets an anonymous client create an attacker-chosen Kerberos identity inside the administrators group. Red Hat reproduced the chain twice, including on a machine with no access, and FreeIPA’s side is fixed in version 4.13.4. The weakness is in how ownership is checked. A client that has never logged in can be treated as “nobody,” so blank ownership fields can pass and the attacker can write both the account and its privileges together. That means the exploit is not only about unauthorized account creation: it can leave a live admin identity behind if those directory entries are not found and removed. For FreeIPA and Red Hat Identity Management operators, the patch closes the software flaw but does not by itself prove the directory is clean. If LDAP-backed admin groups were touched, the lasting exposure is a malicious Kerberos principal that still has administrator rights even after the package is updated.

Part of the PlainSec briefing for 2026-09-08

Editions

Sources