Upstream information
Description
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.Other Security Trackers
SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
| CVSS detail | CNA (Red Hat) |
|---|---|
| Base Score | 9.8 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
| CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- RHSA-2026:70564, published Mon Sep 28 15:07:47 UTC 2026
- RHSA-2026:72279, published Tue Sep 29 15:07:42 UTC 2026
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Liberty Linux 10 |
| Patchnames: RHSA-2026:72279 (x86_64) |
| SUSE Liberty Linux 9 |
| Patchnames: RHSA-2026:70564 (x86_64) |
SUSE Timeline for this CVE
CVE page created: Mon Sep 28 17:43:54 2026CVE page last modified: Thu Oct 1 11:48:36 2026