Skip to main content
EPSS 0.2%top 88%

Red Hat Security Advisory: ipa security, bug fix, and enhancement update

0
Critical
Published: 09/28/2026 (09/28/2026, 05:20:28 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments. Security Fix(es): * ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read (CVE-2026-73198) * ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read (CVE-2026-73197) * FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships (CVE-2026-11861) * freeipa: ipa: FreeIPA/IdM: Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL (CVE-2026-18147) * freeipa: ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes (CVE-2026-19550) * ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore (CVE-2026-13097) * ipa: freeipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI (CVE-2026-76578) * freeIPA: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service (CVE-2026-79678) Bug Fix(es) and Enhancement(s): * [Cursor Automated] Include latest fixes in python3-ipatests package [RHEL10.2] (JIRA:RHEL-173375) * WebUI Hardening [rhel-10.2.z] (JIRA:RHEL-238510) * ipa-otptoken-import hardening [rhel-10.2.z] (JIRA:RHEL-238518) * host-mod: handle the password attribute when set with --setattr userpassword= [rhel-10.2.z] (JIRA:RHEL-238522) * ipa env: support only simple * wildcard [rhel-10.2.z] (JIRA:RHEL-238526) * ipa-epn: drop_privileges method is mixing uid and gid [rhel-10.2.z] (JIRA:RHEL-238673) * ipa-migrate: require Replication Administrator privilege [rhel-10.2.z] (JIRA:RHEL-238676) * ipa-migrate tool is renaming host records & host info in automount information [rhel-10.2.z] (JIRA:RHEL-240768) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
SUSEnoarchipa-client-common-0:4.13.4-1.el10_2.noarchipa-common-0:4.13.4-1.el10_2.noarchipa-selinux-0:4.13.4-1.el10_2.noarchRed HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 10)Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)src

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 07:04:42 UTC

Technical Analysis

A flaw in FreeIPA on Red Hat Enterprise Linux 9 allows authenticated Active Directory users to bypass authentication for FreeIPA services such as the portal, SMB server, and LDAP directory by impersonating a client name in the Ticket Granting Service (TGS). This is due to FreeIPA not verifying Privilege Attribute Certificate (PAC) certificates in trust relationships with Active Directory. Exploitation requires a cross-realm trust, a valid Active Directory account, and the ability to register duplicate or conflicting SPNs in the Active Directory forest. Microsoft mitigations in Windows Server 2012 R2 (with MSKB-3070083) and Windows 11 version 22H2 and later enforce SPN and UPN uniqueness, blocking this attack path on the Windows side. Thus, only environments with outdated or unpatched Active Directory domain controllers remain realistically at risk.

Potential Impact

The vulnerability allows an authenticated Active Directory user to escalate privileges within the FreeIPA domain by bypassing authentication controls. This impacts confidentiality and integrity of FreeIPA services including portal access, SMB server, and LDAP directory. However, practical exploitation is constrained by the need for specific trust configurations and unpatched Active Directory environments. No impact on availability is noted.

Mitigation Recommendations

Red Hat states that no practical mitigation meeting their criteria is currently available. However, Microsoft has addressed the prerequisite conditions by enforcing SPN and UPN uniqueness constraints on patched Windows Server 2012 R2 domain controllers and by default on Windows 11 version 22H2 and later. Therefore, maintaining updated and patched Active Directory domain controllers effectively blocks the attack path. Organizations should ensure their Active Directory environments are fully patched and running supported functional levels to mitigate this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-g67c-jg9c-rqh2
Osv Schema Version
1.4.0
Aliases
["CVE-2026-11861"]
Database Specific Severity
CRITICAL
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a870a4facd9273b49b584fb

Added to database: 08/20/2026, 14:08:15 UTC

Last enriched: 09/24/2026, 07:04:42 UTC

Last updated: 10/05/2026, 06:48:14 UTC

Views: 61

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses