CVE-2026-13097

EUVD-2026-63243
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.7 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 34.73%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
freeipafreeipa
4.12.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freeipa
bookworm
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeipa
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ipa-client
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-encrypted-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-epn
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-samba
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux-luna
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux-nfast
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-encrypted-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-trust-ad
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipaclient
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipalib
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipaserver
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipatests
RHEL 9
0:4.13.4-1.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
ipa-client
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-client-common
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-common
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-debuginfo
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-python-compat
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-server
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-server-common
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-server-dns
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
ipa-server-trust-ad
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
python2-ipaclient
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
python2-ipalib
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed
python2-ipaserver
Amazon Linux 2
0:4.6.8-5.amzn2.17.5
fixed