Description
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
Published: 2026-08-20
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in FreeIPA allows an attacker with authenticated Active Directory credentials to impersonate a client name in the Ticket Granting Service. FreeIPA services do not verify the Privilege Attribute Certificate, so the attacker can gain unauthenticated access to portal, SMB, and LDAP services within the FreeIPA domain. The result is an elevation of privileges and potential full compromise of the FreeIPA environment.

Affected Systems

Red Hat Enterprise Linux 10, 6, 7, 8, and 9 are affected. The vulnerability pertains to the FreeIPA services that run on these operating systems.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.6 and is not yet listed in the CISA KEV catalog. Exploitation requires an existing trust relationship between FreeIPA and Active Directory and an authenticated AD user. Because the attack vector depends on trust configuration, mitigation is best done by disabling unsupported trust relationships or applying vendor patches when available. The lack of a publicly documented EPSS score indicates uncertain current exploitation prevalence, but the high severity score warrants immediate attention.

Generated by OpenCVE AI on August 20, 2026 at 22:32 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Remove or disable the trust relationship between FreeIPA and Active Directory until the vendor releases an update.
  • Apply the latest Red Hat Enterprise Linux security update that resolves the FreeIPA PAC verification issue; if unavailable, monitor the vendor advisory for a patch release.
  • Implement network segmentation and strict access controls around FreeIPA services to limit exposure of the TGS and other authentication mechanisms.

Generated by OpenCVE AI on August 20, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 20 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
Title Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-266
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-20T13:48:25.096Z

Reserved: 2026-06-10T11:21:33.281Z

Link: CVE-2026-11861

cve-icon Vulnrichment

Updated: 2026-08-20T13:48:21.609Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-20T11:16:19.270

Modified: 2026-08-20T14:17:08.387

Link: CVE-2026-11861

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-20T08:00:00Z

Links: CVE-2026-11861 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T22:45:02Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment