Red Hat FreeIPA Authentication Bypass and Privilege Escalation Vulnerabilities (CVE-2026-11861, CVE-2026-13097)

Release Date: 24th August 2026 (Added 1 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate Red Hat FreeIPA, particularly those with a trust relationship configured between FreeIPA and Active Directory. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-11861 and CVE-2026-13097 are authentication bypass and privilege escalation vulnerabilities in FreeIPA. CVE-2026-11861 affects deployments with a trust relationship configured between FreeIPA and Active Directory: because FreeIPA services do not verify Privilege Attribute Certificate (PAC) certificates, an Active Directory user can impersonate a different client name in a Ticket Granting Service (TGS) request and bypass authentication for FreeIPA services, including the web portal, the SMB server, and the LDAP directory.

CVE-2026-13097 is a separate flaw in the underlying 389-ds directory server: its uniqueness constraint on Kerberos principal name attributes does not account for equivalent representations of the same name, so a user with sufficient LDAP write privileges can create a service principal that impersonates an existing, more privileged one. This lets the attacker obtain Kerberos service tickets for sensitive services and, in the worst case, fully compromise the FreeIPA domain.

Reference

  1. https://access.redhat.com/errata/RHSA-2026:16482
  2. https://www.cve.org/CVERecord?id=CVE-2026-11861
  3. https://www.cve.org/CVERecord?id=CVE-2026-13097