Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore
Published Aug 20, 2026
8.7
HIGHCVSS 3.1
EPSS 0.43%
Description
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
|
Configuration 1
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
ipa
Affected
Red Hat Enterprise Linux 6
ipa
Out of support scope
Red Hat Enterprise Linux 7
ipa
Affected
Red Hat Enterprise Linux 8
idm:DL1/ipa
Affected
Red Hat Enterprise Linux 8
idm:client/ipa
Affected
Red Hat Enterprise Linux 8
ipa
Affected
Red Hat Enterprise Linux 9
ipa
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 6 | ipa | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 8 | idm:DL1/ipa | Affected | n/a |
| Red Hat Enterprise Linux 8 | idm:client/ipa | Affected | n/a |
| Red Hat Enterprise Linux 8 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 9 | ipa | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This bug can only be used if the user already has access to the LDAP to a computer account or an account with the right to add to almost any branch of the LDAP directory. Also this bug can be used to corrupt the LDAP privileges but can not be used to launch a Denial of Service since LDAP privileges do not generally coincide with system privileges.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Aug 21, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00427) | 34.64th | v5 (v2026.06.15) |
| Aug 21, 2026 | 0.34% (0.00344) | 27.64th | v5 (v2026.06.15) |
References (6)
- https://access.redhat.com/errata/RHSA-2026:70564 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72279 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-13097 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2515974 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-13097
- https://www.cve.org/CVERecord?id=CVE-2026-13097
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:70564 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:72279 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-13097 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2515974 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-13097 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-13097 |
Change history (0)
No recorded changes yet.