CVE-2026-11861Critical· 9.6▾ MidnightA flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
freeipa < 4.13.3enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Upgrade past the affected range:
freeipa 4.13.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73197High· 7.5A flaw was found in FreeIPA
CVE-2026-73198High· 7.5A flaw was found in FreeIPA
CVE-2026-19550High· 8.2A flaw was found in FreeIPA
CVE-2026-13097High· 8.7A privilege escalation flaw was found in FreeIPA
CVE-2026-84716Medium· 6.6A flaw was found in the automation-controller instance install-bundle endpoint
CVE-2026-49811High· 8.4Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability