Red Hat disclosed CVE-2026-76578 (CVSS 9.8), a critical FreeIPA privilege-escalation flaw that lets an unauthenticated remote LDAP client create an attacker-controlled Kerberos principal and add it to the FreeIPA administrators group. The attack combines FreeIPA’s overly permissive self-service OTP token access-control rule with CVE-2026-76560 in 389 Directory Server, where anonymous clients can satisfy an ownership check when an owner field is empty. Researchers reproduced the attack against a default FreeIPA deployment, producing reusable administrator Kerberos credentials; SID-enabled environments may also permit PAC-bearing tickets that expand access to HTTP and Dogtag services.
RHEL 7, 8, 9, and 10 IPA/IdM components are affected. FreeIPA 4.13.4 addresses the FreeIPA-side issues, while Red Hat released RHEL 9 389 Directory Server updates through RHSA-2026:64781, including fixes for the anonymous LDAP authorization-control bypass, a SASL PLAIN privilege-escalation issue, a heap buffer overflow, and a pre-authentication NULL-pointer dereference. Organizations should urgently apply available updates; until all relevant packages are available, restrict LDAP ports 389 and 636 to trusted hosts and evaluate disabling anonymous LDAP binds. Red Hat reported no public evidence of active exploitation.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Amazon Linux published ALAS-2026-3916 for Amazon Linux 2, updating affected Identity Management (IPA) packages to address critical CVE-2026-76578. The advisory covers IPA client, server, DNS, trust, and related Python packages.
Red Hat published RHSA-2026:64785 for RHEL 10, providing 389-ds-base-3.2.0-10.el10_2 as part of product-specific fixes for the directory-server issues, including CVE-2026-76560.
Red Hat published RHSA-2026:64778 for RHEL 9, updating 389-ds-base, 389-ds-base-libs, and python3-lib389 to remediate four 389 Directory Server flaws. The update includes critical CVE-2026-18922, a SASL PLAIN stale-identity issue that can elevate privileges to Directory Manager, along with overflow, denial-of-service, and LDAP access-control-bypass flaws.
Red Hat published RHSA-2026:64781 for RHEL 9, addressing four 389 Directory Server vulnerabilities and related lib389 replication issues. The advisory provides updates for affected 389-ds-base, 389-ds-base-libs, and python3-lib389 packages.
Four vulnerabilities affecting 389 Directory Server, including CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560, were published. CVE-2026-76560 concerns an anonymous LDAP client's ability to bypass SELFDN ACI bind-rule checks using an empty bind DN.
FreeIPA version 4.13.4 fixes the CVE-2026-76578 chain-related issue and CVE-2026-79678. The latter is an authenticated idp-add input-validation flaw that can expose process environment variables through errors and cause memory exhaustion, though Red Hat stated it cannot be used for code execution.
Red Hat disclosed CVE-2026-76578, a critical FreeIPA flaw that can be chained with 389 Directory Server CVE-2026-76560 to allow an unauthenticated LDAP client to create an attacker-controlled Kerberos principal and obtain FreeIPA administrator-group access. Red Hat reproduced the chain on default FreeIPA deployments and recommended restricting LDAP access and considering disabling anonymous binds until fixes are installed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
11 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcetenable.com
Open sourcethehackernews.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.