Key Facts

Red Hat rates CVE-2026-76578 Critical (CVSS 9.8). It says an unauthenticated LDAP client can combine the issue with a related directory-server flaw to create an attacker-controlled Kerberos principal in the administrators group.

Technical Details

Red Hat says FreeIPA’s self-managed OTP-token access-control rule permits an unauthenticated write path and does not constrain attributes added with a token entry. The vendor reproduced the technique against a default installation.

Impact & Mitigation

Update to the fixed FreeIPA release. Until then, Red Hat recommends restricting LDAP services, typically ports 389 and 636, to trusted hosts; disabling anonymous binds may also block this path after compatibility review.

Sources

By Allan