Privilege Escalation Flaw in FreeIPA by Red Hat
CVE-2026-13097

9.1CRITICAL

What is CVE-2026-13097?

A flaw exists in FreeIPA where the uniqueness constraint for Kerberos principal name attributes in the 389-ds directory server fails to correctly consider equivalent representations of the same principal name. This improperly enforced constraint allows a user with sufficient LDAP write permissions to create a service principal that can impersonate an existing privileged principal. Consequently, this can lead to the unauthorized acquisition of Kerberos service tickets for sensitive services, paving the way for potential full domain compromise.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Vladislav Plyatsok (rd01f) for reporting this issue.
.