Back

HIGH

Apache Kerby: Kerberos Pre-Authentication Bypass

Published Jun 26, 2026

Description

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

Affected products

Remediation

Red Hat statement

This is an Important flaw in Apache Kerby, affecting Red Hat products that utilize Kerberos for authentication, including Red Hat AMQ, JBoss Data Grid, Enterprise Application Platform, and Red Hat JBoss Fuse. The vulnerability allows an attacker to bypass the Kerberos pre-authentication check by sending a specially crafted Pre-Authentication Data (PA-DATA) packet. This circumvents an initial authentication step, potentially leading to unauthorized access or impersonation within a Kerberos-protected environment.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Jun 26, 2026
Updated Aug 3, 2026
Reserved Jun 26, 2026

CISA Vulnrichment

Updated Jun 26, 2026

NVD

Status Deferred
Modified Aug 3, 2026

Red Hat

Severity Important
Public date Jun 26, 2026
Bugzilla 2493407

ENISA EUVD

Assigner apache
Published Jun 26, 2026
Updated Aug 3, 2026

GitHub

No data