Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-11861: FreeIPA lets AD users bypass authentication
CVE-2026-11861 · published 1 month ago
Summary
If you use FreeIPA together with Active Directory trust links, an AD user can pretend to be another client and get access to FreeIPA services such as the web portal, file shares, and directory lookups without proper login. This can let the user gain higher rights inside your FreeIPA environment. Apply the latest security updates for FreeIPA on Red Hat Enterprise Linux 6, 7, 8, and 10, or disable the trust relationship until the patch is installed.
What to do
- Update freeipa freeipa to version 4.13.3 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:14.04:LTS | canonical | freeipa | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | freeipa | All versions |
| Ubuntu:18.04:LTS | canonical | freeipa | All versions |
| Ubuntu:20.04:LTS | canonical | freeipa | All versions |
| Ubuntu:22.04:LTS | canonical | freeipa | All versions |
| Ubuntu:24.04:LTS | canonical | freeipa | All versions |
| Ubuntu:26.04:LTS | canonical | freeipa | All versions |
| – | red hat | red hat enterprise linux 10 | All versions |
| – | red hat | red hat enterprise linux 6 | All versions |
| – | red hat | red hat enterprise linux 7 | All versions |
| – | red hat | red hat enterprise linux 8 | All versions |
| – | red hat | red hat enterprise linux 9 | All versions |
| Debian:12 | debian | freeipa | All versions |
| Debian:13 | debian | freeipa | All versions |
| – | freeipa | freeipa |
< 4.13.3 cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:* |
| – | redhat | enterprise_linux |
7.0 8.0 9.0 10.0 cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* |
Original advisory text
Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
References
- https://access.redhat.com/security/cve/CVE-2026-11861 vdb-entry x_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2487472 issue-tracking x_refsource_REDHAT
- https://security-tracker.debian.org/tracker/CVE-2026-11861 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-11861 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-11861 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:70564 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/downloads/content/package-browser/ URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11861... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-11861 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:72279 vendor-advisory x_refsource_REDHAT
Severity
9.6
Critical
CVSS 3.1: 9.6 (MITRE)
CVSS 3.1: 9.6 (OSV)
Exploitation
EPSS <1%
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published20 Aug 2026
Updated28 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-11861 · NVD
CVE-2026-11861 · MITRE
DEBIAN-CVE-2026-11861 · OSV
UBUNTU-CVE-2026-11861 · OSV
CVE-2026-11861 · OSV
Track software like this
Free during beta