Junglewise Threat Intelligence

CVE-2026-13097: FreeIPA privilege escalation via krbCanonicalName manipulation

CVE-2026-13097 · Severity: high · CVSS 8.7 · Published 2026-08-20

Vendors: Red Hat.

Executive brief

FreeIPA is an open-source identity management system used to centralize authentication and authorization in enterprise environments. A privilege escalation flaw in FreeIPA's LDAP directory server allows users with write privileges to create fake service principals that impersonate legitimate ones, potentially enabling unauthorized access to sensitive services and full domain compromise.

Technical details

The vulnerability is a privilege escalation flaw in FreeIPA's 389-ds directory server caused by improper uniqueness constraint enforcement on Kerberos principal name (krbCanonicalName) attributes. The uniqueness check does not account for equivalent representations of the same principal name, allowing an attacker with LDAP write privileges to create a malicious service principal that impersonates an existing privileged one. This enables unauthorized acquisition of Kerberos service tickets (TGS), leading to potential full domain compromise. The flaw requires the attacker to have existing LDAP write privileges; patches are available in Red Hat Enterprise Linux 9 updates (RHSA-2026:70564).

Affected products

  • Red Hat FreeIPA <UNKNOWN>

Timeline

  • 2026-08-20: disclosed
  • 2026-09-23: patched: RHSA-2026:70564 security advisory released for Red Hat Enterprise Linux 9

References