Back

HIGH

Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore

Published Aug 20, 2026

Description

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.

Affected products

Remediation

Red Hat statement

This bug can only be used if the user already has access to the LDAP to a computer account or an account with the right to add to almost any branch of the LDAP directory. Also this bug can be used to corrupt the LDAP privileges but can not be used to launch a Denial of Service since LDAP privileges do not generally coincide with system privileges.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 20, 2026
Updated Sep 28, 2026
Reserved Jun 23, 2026
CISA Vulnrichment
Updated Aug 21, 2026
NVD
Status Modified
Modified Sep 8, 2026
Red Hat
Severity Important
Public date Aug 20, 2026