Description
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.
Published: 2026-08-20
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A privilege escalation flaw was discovered in FreeIPA. The 389-ds directory server enforces a uniqueness constraint on Kerberos principal names but does not correctly handle different representations of the same principal. This omission allows a user who has LDAP write privileges to create a service principal that impersonates an existing privileged one, thereby obtaining Kerberos service tickets for sensitive services. The resulting access could culminate in a full domain compromise.

Affected Systems

Affected systems include Red Hat Enterprise Linux 6, 7, 8, 9 and 10 running FreeIPA, since the vulnerability resides in the FreeIPA LDAP datastore used on those operating‑system releases.

Risk and Exploitability

The flaw carries a CVSS score of 8.7. The EPSS score is 0.00329, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker already possesses LDAP write permissions, after which the attacker can create a rogue service principal that matches an existing privileged principal and impersonate it. Given the high severity and the potential for domain‑wide compromise, the risk is significant until Red Hat releases a patch or an effective mitigation.

Generated by OpenCVE AI on August 28, 2026 at 19:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict LDAP write permissions to essential administrators only, eliminating any accounts with unnecessary write rights that could create service principals.
  • Configure and enforce Kerberos principal name uniqueness checks in FreeIPA, if available, to prevent equivalent principal name entries from being accepted.
  • Enable and monitor FreeIPA audit logs for the creation of new service principals, and set alerts for suspicious activity involving privileged principal names.
  • If a patch is posted, apply the corresponding Red Hat errata for FreeIPA; otherwise, consult Red Hat security advisories for guidance.

Generated by OpenCVE AI on August 28, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Mon, 24 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Freeipa
Freeipa freeipa
CPEs cpe:2.3:a:freeipa:freeipa:4.12.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Freeipa
Freeipa freeipa

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 20 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.
Title Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-706
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Freeipa Freeipa
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-08T10:49:24.191Z

Reserved: 2026-06-23T19:29:29.484Z

Link: CVE-2026-13097

cve-icon Vulnrichment

Updated: 2026-08-21T18:12:05.557Z

cve-icon NVD

Status : Modified

Published: 2026-08-20T11:16:20.293

Modified: 2026-09-08T11:17:41.063

Link: CVE-2026-13097

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-20T10:19:07Z

Links: CVE-2026-13097 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:30:16Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference