Red Hat Security Advisory: ipa security, bug fix, and enhancement update
Description
Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments. Security Fix(es): * ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read (CVE-2026-73198) * ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read (CVE-2026-73197) * FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships (CVE-2026-11861) * freeipa: ipa: FreeIPA/IdM: Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL (CVE-2026-18147) * freeipa: ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes (CVE-2026-19550) * ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore (CVE-2026-13097) * ipa: freeipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI (CVE-2026-76578) * freeIPA: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service (CVE-2026-79678) Bug Fix(es) and Enhancement(s): * [Cursor Automated] Include latest fixes in python3-ipatests package [RHEL10.2] (JIRA:RHEL-173375) * WebUI Hardening [rhel-10.2.z] (JIRA:RHEL-238510) * ipa-otptoken-import hardening [rhel-10.2.z] (JIRA:RHEL-238518) * host-mod: handle the password attribute when set with --setattr userpassword= [rhel-10.2.z] (JIRA:RHEL-238522) * ipa env: support only simple * wildcard [rhel-10.2.z] (JIRA:RHEL-238526) * ipa-epn: drop_privileges method is mixing uid and gid [rhel-10.2.z] (JIRA:RHEL-238673) * ipa-migrate: require Replication Administrator privilege [rhel-10.2.z] (JIRA:RHEL-238676) * ipa-migrate tool is renaming host records & host info in automount information [rhel-10.2.z] (JIRA:RHEL-240768) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A flaw in FreeIPA on Red Hat Enterprise Linux 9 allows authenticated Active Directory users to bypass authentication for FreeIPA services such as the portal, SMB server, and LDAP directory by impersonating a client name in the Ticket Granting Service (TGS). This is due to FreeIPA not verifying Privilege Attribute Certificate (PAC) certificates in trust relationships with Active Directory. Exploitation requires a cross-realm trust, a valid Active Directory account, and the ability to register duplicate or conflicting SPNs in the Active Directory forest. Microsoft mitigations in Windows Server 2012 R2 (with MSKB-3070083) and Windows 11 version 22H2 and later enforce SPN and UPN uniqueness, blocking this attack path on the Windows side. Thus, only environments with outdated or unpatched Active Directory domain controllers remain realistically at risk.
Potential Impact
The vulnerability allows an authenticated Active Directory user to escalate privileges within the FreeIPA domain by bypassing authentication controls. This impacts confidentiality and integrity of FreeIPA services including portal access, SMB server, and LDAP directory. However, practical exploitation is constrained by the need for specific trust configurations and unpatched Active Directory environments. No impact on availability is noted.
Mitigation Recommendations
Red Hat states that no practical mitigation meeting their criteria is currently available. However, Microsoft has addressed the prerequisite conditions by enforcing SPN and UPN uniqueness constraints on patched Windows Server 2012 R2 domain controllers and by default on Windows 11 version 22H2 and later. Therefore, maintaining updated and patched Active Directory domain controllers effectively blocks the attack path. Organizations should ensure their Active Directory environments are fully patched and running supported functional levels to mitigate this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-g67c-jg9c-rqh2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-11861"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a870a4facd9273b49b584fb
Added to database: 08/20/2026, 14:08:15 UTC
Last enriched: 09/24/2026, 07:04:42 UTC
Last updated: 10/05/2026, 06:48:14 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.