Red Hat disclosed CVE-2026-11861, a FreeIPA privilege-escalation flaw affecting deployments that maintain a trust relationship with Active Directory. In vulnerable environments, an authenticated AD user can impersonate a client name in a Kerberos Ticket Granting Service (TGS) request and bypass authentication to FreeIPA services because affected components trust the TGS cname field and do not properly verify Privilege Attribute Certificate (PAC) certificates. Red Hat said the issue can affect the FreeIPA portal, SMB server, LDAP directory, and likely other GSSAPI-enabled services, creating a path to privilege escalation inside the FreeIPA domain.
The vendor assigned the bug a CVSS 9.6 score but rated it Moderate because exploitation depends on uncommon prerequisites, including a configured FreeIPA-AD cross-realm trust, valid AD credentials, and an AD setup that allows a duplicate or conflicting SPN condition. Red Hat listed ipa packages in RHEL 7, 8, 9, and 10 as affected, while noting that patched and modern Microsoft environments—including Windows Server 2012 R2 with MSKB-3070083 and newer defaults such as Windows 11 22H2—can block the attack path on the AD side. No mitigation meeting Red Hat Product Security criteria was available at publication time, and defenders were urged to review trust relationships, enforce SPN and UPN uniqueness, and monitor for vendor fixes.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat's CVE entry states that CVE-2026-11861 was made public on August 20, 2026. The disclosure described a FreeIPA privilege-escalation flaw affecting environments with FreeIPA-Active Directory trust relationships.
Red Hat Bugzilla 2487472 documented a vulnerability in FreeIPA deployments that trust Active Directory, where an AD user could impersonate a cname in a Kerberos TGS request to bypass authentication to FreeIPA services and potentially escalate privileges.
The CVE identifier CVE-2026-11861 was reserved for the FreeIPA and Active Directory trust authentication bypass issue. The referenced reporting ties the reservation to June 10, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourceaccess.redhat.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.