Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-11861: FreeIPA lets AD users bypass authentication

CVE-2026-11861 · published 1 month ago
Summary

If you use FreeIPA together with Active Directory trust links, an AD user can pretend to be another client and get access to FreeIPA services such as the web portal, file shares, and directory lookups without proper login. This can let the user gain higher rights inside your FreeIPA environment. Apply the latest security updates for FreeIPA on Red Hat Enterprise Linux 6, 7, 8, and 10, or disable the trust relationship until the patch is installed.

What to do
  • Update freeipa freeipa to version 4.13.3 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:14.04:LTS canonical freeipa All versions
Ubuntu:Pro:16.04:LTS canonical freeipa All versions
Ubuntu:18.04:LTS canonical freeipa All versions
Ubuntu:20.04:LTS canonical freeipa All versions
Ubuntu:22.04:LTS canonical freeipa All versions
Ubuntu:24.04:LTS canonical freeipa All versions
Ubuntu:26.04:LTS canonical freeipa All versions
– red hat red hat enterprise linux 10 All versions
– red hat red hat enterprise linux 6 All versions
– red hat red hat enterprise linux 7 All versions
– red hat red hat enterprise linux 8 All versions
– red hat red hat enterprise linux 9 All versions
Debian:12 debian freeipa All versions
Debian:13 debian freeipa All versions
– freeipa freeipa < 4.13.3
cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*
– redhat enterprise_linux 7.0
8.0
9.0
10.0
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Original advisory text
Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
Severity
9.6 Critical
CVSS 3.1: 9.6 (MITRE)
CVSS 3.1: 9.6 (OSV)
Exploitation
EPSS <1%
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published20 Aug 2026
Updated28 Sep 2026
First seen20 Aug 2026
Track software like this
Free during beta