Vendor
critical
advisory
Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw
3 TTPs 3 CVEsAn unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.
FreeIPA +2
identity-management
authentication-bypass
privilege-escalation
ldap
vulnerability
cve
linux
3t
3c
updated
high
advisory
Privilege Escalation in FreeIPA via Kerberos Principal Name Collision
1 TTP 1 CVECVE-2026-13097 is a privilege escalation vulnerability in FreeIPA where the 389-ds directory server fails to enforce uniqueness constraints on Kerberos principal names, allowing attackers with LDAP write access to impersonate privileged service principals.
FreeIPA
privilege-escalation
identity-management
kerberos
1t
1c