CVE-2026-11861

EUVD-2026-63245
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.6 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 11.63%
Affected Products (NVD)
VendorProductVersion
freeipafreeipa
𝑥
< 4.13.3
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freeipa
bookworm
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeipa
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ipa-client
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-encrypted-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-epn
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-samba
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux-luna
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux-nfast
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-encrypted-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-trust-ad
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipaclient
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipalib
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipaserver
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipatests
RHEL 9
0:4.13.4-1.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
ipa-client
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-client-common
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-common
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-debuginfo
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-python-compat
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-server
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-server-common
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-server-dns
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-server-trust-ad
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
python2-ipaclient
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
python2-ipalib
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
python2-ipaserver
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed