Back

HIGH

Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes

Published Aug 11, 2026

Description

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.

Affected products

Remediation

Vendor solution

This issue is fixed upstream. Administrators should apply this fix once available for their platform. Until then, the previously suggested compensating control (restricting "System: Read Trust Information" so it is not granted to all authenticated users) remains a valid interim workaround, with the same caveat that doing so may affect SSSD subdomain support, which relies on that permission's default breadth.

Red Hat statement

This flaw only affects Identity Management (IdM/FreeIPA) servers where a cross-forest trust with Active Directory has been established (via ipa-adtrust-install and ipa trust-add). Servers without an active AD trust are not affected, since the trust object and the ADTRUST component required to reach the vulnerable code path do not exist in that configuration. Exploitation requires an ordinary, non-administrative IdM user account to trigger the vulnerable trust-fetch-domains command against a server of the attacker's choosing — no delegated administrative privilege of any kind is required. On its own, this lets an authenticated non-admin user force the IdM server to launch a privileged helper process and initiate a network connection to attacker-controlled infrastructure. Impersonating accounts in the trusted Active Directory domain — additionally requires the attacker to intercept and relay the resulting Kerberos authentication traffic, force a downgrade to the weaker encrypted-timestamp pre-authentication mechanism, and successfully recover the trust's interrealm secret through that downgrade.

Red Hat mitigation

This issue is fixed upstream. Administrators should apply this fix once available for their platform. Until then, the previously suggested compensating control (restricting "System: Read Trust Information" so it is not granted to all authenticated users) remains a valid interim workaround, with the same caveat that doing so may affect SSSD subdomain support, which relies on that permission's default breadth.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 11, 2026
Updated Sep 28, 2026
Reserved Aug 11, 2026
CISA Vulnrichment
Updated Aug 12, 2026
NVD
Status Analyzed
Modified Aug 25, 2026
Red Hat
Severity Important
Public date Aug 11, 2026