Impact
A flaw was discovered in FreeIPA’s self‑managed OTP token ACI that allows an unauthenticated LDAP client to create arbitrary Kerberos principals and add them to the administrators group. The flaw exists because the ACI does not require authentication and does not restrict the attributes that can be added. An attacker can generate a legitimate administrator‑group member and then perform any administrative operation against the directory and, on SID-enabled deployments, other Identity Management services. This represents a critical privilege escalation without needing any initial credentials.
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, 9, and 10 are affected. The vulnerability manifests in the FreeIPA components bundled with these operating systems, impacting any system that hosts a FreeIPA directory service on those releases.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity and the vulnerability can be exploited remotely from any host that can reach the LDAP service on ports 389 or 636. The lack of authentication required for the LDAP client, combined with the flaw in the underlying directory server’s ACI evaluation, provides a straightforward attack path for an unauthenticated attacker. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS score and remote nature mean that active exploitation is plausible. The likelihood of exploitation is high if the LDAP service is exposed to untrusted networks.
OpenCVE Enrichment