<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afreeipafreeipa/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 07 Sep 2026 13:36:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afreeipafreeipa/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw</title><link>https://feed.craftedsignal.io/briefs/2026-09-freeipa-otp-bypass/</link><pubDate>Mon, 07 Sep 2026 13:36:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-freeipa-otp-bypass/</guid><description>An unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.</description><content:encoded><![CDATA[<p>A critical vulnerability (CVE-2026-76578) exists within FreeIPA's self-managed OTP token mechanism. The Access Control Instructions (ACI) associated with self-managed tokens fail to enforce authentication requirements and do not validate attributes added alongside a token entry. An unauthenticated attacker can interact with the LDAP interface to inject arbitrary attributes. When chained with a related, independently tracked vulnerability in the underlying 389 Directory Server's ACI evaluation logic, the attacker can successfully create a malicious Kerberos principal and append it to the administrator group. This enables full administrative control over the FreeIPA environment, including directory management and potential impact on integrated IdM services in SID-enabled deployments. Because the attack originates from the network-accessible LDAP service without requiring prior authentication, it poses a severe risk to identity infrastructure.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify accessible LDAP interfaces (port 389/636) on the target FreeIPA instance.</li>
<li>Attacker crafts a malicious LDAP packet targeting the self-managed OTP token endpoint.</li>
<li>Attacker bypasses missing authentication checks within the vulnerable OTP ACI implementation.</li>
<li>Attacker injects arbitrary attributes into the directory entry, bypassing existing input validation constraints.</li>
<li>Attacker leverages a secondary ACI evaluation vulnerability in the underlying directory server to elevate privileges for the injected principal.</li>
<li>Attacker creates an unauthorized Kerberos principal and associates it with the administrator group in the LDAP backend.</li>
<li>Attacker authenticates as the newly created administrative principal to obtain a legitimate Kerberos ticket-granting ticket (TGT).</li>
<li>Attacker performs administrative operations, such as user modification or full directory exfiltration, gaining total control over IdM services.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in complete administrative compromise of the FreeIPA environment. An attacker can gain unauthorized membership in the administrator group, allowing them to modify sensitive identity records, access secret keys, and manage all IdM services. In deployments where SID mapping is enabled, this compromise may extend to integrated Windows environments and other services relying on the IdM instance, leading to large-scale credential theft and persistent unauthorized access.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately audit all FreeIPA and underlying 389 Directory Server installations to confirm version compatibility with patches for CVE-2026-76578.</li>
<li>Implement strict firewall rules to restrict network-based LDAP (389/636) access to authorized management subnets only.</li>
<li>Monitor directory server access logs for anomalous LDAP bind or entry modification attempts targeting OTP token attributes or unauthorized additions to the admin group.</li>
<li>Review administrative group membership logs for recently created or unknown Kerberos principals.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>identity-management</category><category>authentication-bypass</category><category>privilege-escalation</category><category>ldap</category><category>vulnerability</category><category>cve</category><category>linux</category></item></channel></rss>