FreeIPA flaw chain lets anonymous clients grant themselves admin credentials
Red Hat disclosed a flaw chain in FreeIPA, the identity-management system that controls logins across Linux domains, that lets a client which never authenticated create an administrator account for itself. The FreeIPA flaw, CVE-2026-76578 and rated 9.8, is an access rule that lets anyone write a one-time-password token without logging in, and does not restrict what else is written alongside it. The second flaw, CVE-2026-76560 in the underlying 389 Directory Server, treats an unauthenticated client's empty name as matching an empty ownership field, so it passes an owner-only check by being nobody. Together they let an anonymous client write a Kerberos identity into the administrators group; a default install is affected.
- Check
- Apply Red Hat's updates for FreeIPA and 389 Directory Server as soon as available, and audit your directory for unexpected Kerberos identities and accounts recently added to the administrators group.
- Affected
- Organizations running FreeIPA or Red Hat Identity Management (CVE-2026-76578, CVE-2026-76560); an unauthenticated client can create an admin-level Kerberos identity, and a default install is vulnerable, putting the whole identity system at risk.
- Fix
- Patch FreeIPA and the directory server promptly, restrict who can reach the directory service over the network, hunt for rogue tokens and admin accounts, and rotate credentials if abuse is found.