Skip to content
Threat Feed

Product

FreeIPA

4 briefs RSS
critical advisory

Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw

An unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.

FreeIPA +2 identity-management authentication-bypass privilege-escalation ldap vulnerability cve linux
3t 3c updated
low advisory

Denial of Service Vulnerability in FreeIPA Migration Handler

An unauthenticated remote denial-of-service vulnerability in FreeIPA, tracked as CVE-2026-73197, allows attackers to exhaust system memory by sending oversized form POST requests to the migration endpoint.

FreeIPA +4 denial-of-service vulnerability cve-2026-73197
1r 1t 1c
high advisory

Privilege Escalation in FreeIPA via Kerberos Principal Name Collision

CVE-2026-13097 is a privilege escalation vulnerability in FreeIPA where the 389-ds directory server fails to enforce uniqueness constraints on Kerberos principal names, allowing attackers with LDAP write access to impersonate privileged service principals.

FreeIPA privilege-escalation identity-management kerberos
1t 1c
critical advisory

CVE-2026-11610: 389 Directory Server SASL Heap Buffer Overflow Leading to DoS

A heap buffer overflow vulnerability (CVE-2026-11610) exists in the SASL I/O layer of 389 Directory Server (389-ds-base), active since version 1.3.2. An authenticated attacker can send a specially crafted, oversized LDAP UNBIND packet after a successful SASL bind with integrity protection. This causes approximately 2 megabytes of attacker-controlled data to overflow a 512-byte heap buffer in sasl_io_recv(), leading to a denial of service (server crash).

389 Directory Server +2 heap-overflow denial-of-service ldap sasl linux cve
1t 1c