{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afreeipafreeipa/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-76578"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FreeIPA (all versions)","FreeIPA"],"_cs_severities":["critical"],"_cs_tags":["identity-management","authentication-bypass","privilege-escalation","ldap","vulnerability","cve","linux"],"_cs_type":"advisory","_cs_vendors":["FreeIPA"],"content_html":"\u003cp\u003eA critical vulnerability (CVE-2026-76578) exists within FreeIPA's self-managed OTP token mechanism. The Access Control Instructions (ACI) associated with self-managed tokens fail to enforce authentication requirements and do not validate attributes added alongside a token entry. An unauthenticated attacker can interact with the LDAP interface to inject arbitrary attributes. When chained with a related, independently tracked vulnerability in the underlying 389 Directory Server's ACI evaluation logic, the attacker can successfully create a malicious Kerberos principal and append it to the administrator group. This enables full administrative control over the FreeIPA environment, including directory management and potential impact on integrated IdM services in SID-enabled deployments. Because the attack originates from the network-accessible LDAP service without requiring prior authentication, it poses a severe risk to identity infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify accessible LDAP interfaces (port 389/636) on the target FreeIPA instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious LDAP packet targeting the self-managed OTP token endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker bypasses missing authentication checks within the vulnerable OTP ACI implementation.\u003c/li\u003e\n\u003cli\u003eAttacker injects arbitrary attributes into the directory entry, bypassing existing input validation constraints.\u003c/li\u003e\n\u003cli\u003eAttacker leverages a secondary ACI evaluation vulnerability in the underlying directory server to elevate privileges for the injected principal.\u003c/li\u003e\n\u003cli\u003eAttacker creates an unauthorized Kerberos principal and associates it with the administrator group in the LDAP backend.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates as the newly created administrative principal to obtain a legitimate Kerberos ticket-granting ticket (TGT).\u003c/li\u003e\n\u003cli\u003eAttacker performs administrative operations, such as user modification or full directory exfiltration, gaining total control over IdM services.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in complete administrative compromise of the FreeIPA environment. An attacker can gain unauthorized membership in the administrator group, allowing them to modify sensitive identity records, access secret keys, and manage all IdM services. In deployments where SID mapping is enabled, this compromise may extend to integrated Windows environments and other services relying on the IdM instance, leading to large-scale credential theft and persistent unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately audit all FreeIPA and underlying 389 Directory Server installations to confirm version compatibility with patches for CVE-2026-76578.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall rules to restrict network-based LDAP (389/636) access to authorized management subnets only.\u003c/li\u003e\n\u003cli\u003eMonitor directory server access logs for anomalous LDAP bind or entry modification attempts targeting OTP token attributes or unauthorized additions to the admin group.\u003c/li\u003e\n\u003cli\u003eReview administrative group membership logs for recently created or unknown Kerberos principals.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T13:36:29Z","date_published":"2026-09-07T13:36:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-freeipa-otp-bypass/","summary":"An unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.","title":"Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw","url":"https://feed.craftedsignal.io/briefs/2026-09-freeipa-otp-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}