CVE-2026-76578 is a critical missing-authentication flaw in FreeIPA’s self-managed OTP token access-control instruction (ACI). The ACI permits unauthenticated LDAP clients to create an OTP token entry and fails to constrain additional attributes supplied in the same operation. When chained with CVE-2026-76560, a 389 Directory Server ACI-evaluation flaw, an attacker can create an arbitrary Kerberos principal with attacker-controlled attributes and add it to the FreeIPA administrators group.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated, network-accessible authentication-bypass and privilege-escalation vulnerability in FreeIPA/Red Hat Identity Management. The OTP token ACI improperly permits unauthenticated access and insufficiently restricts added attributes, enabling an attacker to obtain FreeIPA administrator-group membership and full administrative control when chained with a directory-server ACI evaluation issue.
A critical FreeIPA access-control flaw that, when chained with CVE-2026-76560 in 389 Directory Server, allows an unauthenticated client to create an attacker-selected Kerberos identity and obtain reusable administrator credentials.
An unauthenticated privilege-escalation flaw in FreeIPA's self-managed OTP token access-control instruction (ACI). In combination with a separately tracked directory-server ACI-evaluation flaw, a remote attacker can create an attacker-controlled Kerberos principal, add it to the FreeIPA administrators group, and conduct administrative operations against the directory and, on SID-enabled deployments, other IdM services.
A critical FreeIPA access-control flaw in the self-managed OTP token ACI. It permits an unauthenticated LDAP client, when chained with a separately tracked directory-server ACI-evaluation flaw, to create an attacker-controlled Kerberos principal with FreeIPA administrator-group membership, enabling administrative operations against the directory and, on SID-enabled deployments, other IdM services.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.