Threat Intelligence

Critical FreeIPA Bug Lets Anonymous Users Create Their Own Admin Account

The Hacker News · 8 Sept 2026
Key Takeaway Australian businesses running FreeIPA or Red Hat Identity Management should update to version 4.13.4 or later immediately to close off this admin-creation pathway.

Red Hat has disclosed a serious vulnerability chain affecting FreeIPA, the system many Linux organisations use to control who can log in across a domain. The flaw allows a client that has never authenticated to create its own Kerberos identity and password, and land itself in the administrators group, effectively granting itself top-level access from nothing.

The issue stems from two separate bugs working together. FreeIPA includes a rule allowing users to manage their own one-time-password token without requiring prior login, and places no limits on what else can be written alongside that token. Separately, the underlying 389 Directory Server has an access control rule meant to restrict changes to an entry's authenticated owner, but it compares names as plain text, meaning an anonymous client with no name matches an empty stored value. Combined, this lets an anonymous user write a new administrator identity while technically passing the ownership check. Red Hat reproduced this on default installations, including one with no access at all.

The FreeIPA-specific flaw (CVE-2026-76578) is rated critical with a preliminary CVSS score of 9.8 and has been fixed in version 4.13.4. The directory server flaw (CVE-2026-76560) is rated 7.5 and only poses a risk where a deployment uses a similarly shaped access rule, which FreeIPA does by default.

FreeIPA vulnerability identity management Linux security Red Hat

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.