Executive brief
FreeIPA is a centralized identity and authentication system used by enterprises to manage user access and permissions. A critical flaw in the self-managed OTP token feature allows unauthenticated attackers to create arbitrary administrator accounts and gain full control of the identity management system, compromising all user accounts and services that depend on it for authentication.
Technical details
The vulnerability exists in FreeIPA's Access Control Instructions (ACI) for self-managed OTP tokens, which does not require authentication and does not validate which attributes may be added to token entries. An unauthenticated LDAP client can exploit this flaw in conjunction with a related ACI evaluation bug in the underlying directory server to create an arbitrary Kerberos principal, add it to the administrators group, and obtain genuine FreeIPA administrator-group membership. This enables remote, unauthenticated attackers to perform arbitrary administrative operations against the directory and, on SID-enabled deployments, other Identity Management services. The vulnerability requires no user interaction or special preconditions beyond network access to the LDAP service.
Affected products
- Red Hat FreeIPA versions prior to RHSA-2026:70564 patch
Timeline
- 2026-09-07: disclosed: CVE-2026-76578 published
- 2026-09-23: advisory: Red Hat RHSA-2026:70564 security advisory issued