Critical FreeIPA Bug Lets Anonymous Users Create Their Own Admin Account
Red Hat has disclosed a serious vulnerability chain affecting FreeIPA, the system many Linux organisations use to control who can log in across a domain. The flaw allows a client that has never authenticated to create its own Kerberos identity and password, and land itself in the administrators group, effectively granting itself top-level access from nothing.
The issue stems from two separate bugs working together. FreeIPA includes a rule allowing users to manage their own one-time-password token without requiring prior login, and places no limits on what else can be written alongside that token. Separately, the underlying 389 Directory Server has an access control rule meant to restrict changes to an entry's authenticated owner, but it compares names as plain text, meaning an anonymous client with no name matches an empty stored value. Combined, this lets an anonymous user write a new administrator identity while technically passing the ownership check. Red Hat reproduced this on default installations, including one with no access at all.
The FreeIPA-specific flaw (CVE-2026-76578) is rated critical with a preliminary CVSS score of 9.8 and has been fixed in version 4.13.4. The directory server flaw (CVE-2026-76560) is rated 7.5 and only poses a risk where a deployment uses a similarly shaped access rule, which FreeIPA does by default.