CVE-2026-13097
EUVD-2026-6324320.08.2026, 11:16
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
| freeipa | freeipa | 4.12.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| ipa-client |
| ||
| ipa-client-common |
| ||
| ipa-client-encrypted-dns |
| ||
| ipa-client-epn |
| ||
| ipa-client-samba |
| ||
| ipa-common |
| ||
| ipa-selinux |
| ||
| ipa-selinux-luna |
| ||
| ipa-selinux-nfast |
| ||
| ipa-server |
| ||
| ipa-server-common |
| ||
| ipa-server-dns |
| ||
| ipa-server-encrypted-dns |
| ||
| ipa-server-trust-ad |
| ||
| python3-ipaclient |
| ||
| python3-ipalib |
| ||
| python3-ipaserver |
| ||
| python3-ipatests |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| ipa-client |
| ||
| ipa-client-common |
| ||
| ipa-common |
| ||
| ipa-debuginfo |
| ||
| ipa-python-compat |
| ||
| ipa-server |
| ||
| ipa-server-common |
| ||
| ipa-server-dns |
| ||
| ipa-server-trust-ad |
| ||
| python2-ipaclient |
| ||
| python2-ipalib |
| ||
| python2-ipaserver |
|
Common Weakness Enumeration