{"id":"CVE-2026-76578","title":"A flaw was found in FreeIPA","summary":"A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a r…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"Red Hat","product":"ipa","affected":["ipa (all versions)","ipa","ipa (all versions)","idm:client/ipa (all versions)","ipa (all versions)","ipa (all versions)"],"published":"2026-09-07","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:08:15.590","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76578","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-76578","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2519522","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76578.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76578"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76578"}],"tags":["nvd","cve.org","csaf","vex","red-hat","exploit-available"],"epss":0.00453,"epssPercentile":0.38587,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-08T13:58:12.782701Z"},"ingestedAt":"2026-09-08T15:33:26.977Z","exploits":{"github":1,"githubRepos":["https://github.com/BrainBob/CVE-2026-76578"],"checkedAt":"2026-09-21T15:30:40.973Z"},"exploitAvailable":true,"slug":"CVE-2026-76578","body":"## Overview\n\nA flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Critical · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76578.json)","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":201915,"id":"CVE-2026-76578","ts":1789399986230,"field":"exploit_available","old":"false","new":"true"},{"seq":200645,"id":"CVE-2026-76578","ts":1789397562261,"field":"exploit_available","old":"true","new":"false"},{"seq":199352,"id":"CVE-2026-76578","ts":1789395471867,"field":"exploit_available","old":"false","new":"true"},{"seq":198597,"id":"CVE-2026-76578","ts":1789392166242,"field":"exploit_available","old":"true","new":"false"},{"seq":198552,"id":"CVE-2026-76578","ts":1789392092273,"field":"exploit_available","old":"false","new":"true"},{"seq":196343,"id":"CVE-2026-76578","ts":1789383734454,"field":"exploit_available","old":"true","new":"false"},{"seq":195272,"id":"CVE-2026-76578","ts":1789380553931,"field":"exploit_available","old":"false","new":"true"},{"seq":194059,"id":"CVE-2026-76578","ts":1789378658655,"field":"exploit_available","old":"true","new":"false"},{"seq":192846,"id":"CVE-2026-76578","ts":1789376487876,"field":"exploit_available","old":"false","new":"true"},{"seq":191633,"id":"CVE-2026-76578","ts":1789373580893,"field":"exploit_available","old":"true","new":"false"},{"seq":190418,"id":"CVE-2026-76578","ts":1789369427476,"field":"exploit_available","old":"false","new":"true"},{"seq":189205,"id":"CVE-2026-76578","ts":1789368354916,"field":"exploit_available","old":"true","new":"false"},{"seq":187988,"id":"CVE-2026-76578","ts":1789365207863,"field":"exploit_available","old":"false","new":"true"},{"seq":186775,"id":"CVE-2026-76578","ts":1789363436333,"field":"exploit_available","old":"true","new":"false"},{"seq":185561,"id":"CVE-2026-76578","ts":1789361192003,"field":"exploit_available","old":"false","new":"true"},{"seq":184348,"id":"CVE-2026-76578","ts":1789358299719,"field":"exploit_available","old":"true","new":"false"},{"seq":182599,"id":"CVE-2026-76578","ts":1789354297867,"field":"exploit_available","old":"false","new":"true"},{"seq":181392,"id":"CVE-2026-76578","ts":1789353262163,"field":"exploit_available","old":"true","new":"false"},{"seq":180185,"id":"CVE-2026-76578","ts":1789350252669,"field":"exploit_available","old":"false","new":"true"},{"seq":178978,"id":"CVE-2026-76578","ts":1789348249577,"field":"exploit_available","old":"true","new":"false"},{"seq":177771,"id":"CVE-2026-76578","ts":1789346351010,"field":"exploit_available","old":"false","new":"true"},{"seq":176564,"id":"CVE-2026-76578","ts":1789343153699,"field":"exploit_available","old":"true","new":"false"},{"seq":174681,"id":"CVE-2026-76578","ts":1789334847346,"field":"exploit_available","old":"false","new":"true"},{"seq":173476,"id":"CVE-2026-76578","ts":1789333628406,"field":"exploit_available","old":"true","new":"false"},{"seq":172290,"id":"CVE-2026-76578","ts":1789331073404,"field":"exploit_available","old":"false","new":"true"},{"seq":171104,"id":"CVE-2026-76578","ts":1789328735255,"field":"exploit_available","old":"true","new":"false"},{"seq":169899,"id":"CVE-2026-76578","ts":1789327137164,"field":"exploit_available","old":"false","new":"true"},{"seq":168694,"id":"CVE-2026-76578","ts":1789323793325,"field":"exploit_available","old":"true","new":"false"},{"seq":167489,"id":"CVE-2026-76578","ts":1789319663444,"field":"exploit_available","old":"false","new":"true"},{"seq":166284,"id":"CVE-2026-76578","ts":1789318720713,"field":"exploit_available","old":"true","new":"false"},{"seq":165079,"id":"CVE-2026-76578","ts":1789315768988,"field":"exploit_available","old":"false","new":"true"},{"seq":163874,"id":"CVE-2026-76578","ts":1789313589738,"field":"exploit_available","old":"true","new":"false"},{"seq":162669,"id":"CVE-2026-76578","ts":1789311881765,"field":"exploit_available","old":"false","new":"true"},{"seq":161464,"id":"CVE-2026-76578","ts":1789308679666,"field":"exploit_available","old":"true","new":"false"},{"seq":159577,"id":"CVE-2026-76578","ts":1789300451475,"field":"exploit_available","old":"false","new":"true"},{"seq":156566,"id":"CVE-2026-76578","ts":1789294723021,"field":"exploit_available","old":"true","new":"false"},{"seq":155361,"id":"CVE-2026-76578","ts":1789292905120,"field":"exploit_available","old":"false","new":"true"},{"seq":154156,"id":"CVE-2026-76578","ts":1789289749064,"field":"exploit_available","old":"true","new":"false"},{"seq":152806,"id":"CVE-2026-76578","ts":1789281643080,"field":"exploit_available","old":"false","new":"true"},{"seq":152446,"id":"CVE-2026-76578","ts":1789281224098,"field":"exploit_available","old":"true","new":"false"},{"seq":151407,"id":"CVE-2026-76578","ts":1789277607036,"field":"exploit_available","old":"false","new":"true"},{"seq":150368,"id":"CVE-2026-76578","ts":1789276209227,"field":"exploit_available","old":"true","new":"false"},{"seq":149335,"id":"CVE-2026-76578","ts":1789273803239,"field":"exploit_available","old":"false","new":"true"},{"seq":148302,"id":"CVE-2026-76578","ts":1789271293981,"field":"exploit_available","old":"true","new":"false"},{"seq":146334,"id":"CVE-2026-76578","ts":1789269353803,"field":"exploit_available","old":"false","new":"true"},{"seq":145139,"id":"CVE-2026-76578","ts":1789266300067,"field":"exploit_available","old":"true","new":"false"},{"seq":144043,"id":"CVE-2026-76578","ts":1789262585645,"field":"exploit_available","old":"false","new":"true"},{"seq":142947,"id":"CVE-2026-76578","ts":1789261485623,"field":"exploit_available","old":"true","new":"false"},{"seq":141778,"id":"CVE-2026-76578","ts":1789258810749,"field":"exploit_available","old":"false","new":"true"},{"seq":140619,"id":"CVE-2026-76578","ts":1789256700206,"field":"exploit_available","old":"true","new":"false"}]}