
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11861 is a critical authentication bypass and privilege escalation vulnerability in FreeIPA affecting deployments configured with an Active Directory (AD) cross-realm trust relationship. The flaw allows authenticated AD users to impersonate arbitrary client names in the Kerberos Ticket Granting Service (TGS) because FreeIPA services do not verify Privilege Attribute Certificate (PAC) certificates, enabling unauthorized access to FreeIPA services including the web portal, SMB server, and LDAP directory. It was reported on June 10, 2026, and publicly disclosed on August 20, 2026, with credit to researcher Vladislav Plyatsok (rd01f) (Red Hat CVE). The vulnerability carries a CVSS v3.1 base score of 9.6 (Critical) (GitHub Advisory, Red Hat CVE).
The root cause is classified as CWE-266 (Incorrect Privilege Assignment): FreeIPA GSSAPI services trust the cname field in TGS tickets without validating the accompanying Privilege Attribute Certificate (PAC), which is the Kerberos mechanism used to convey authorization data including group memberships and privileges (Red Hat CVE, Red Hat Bugzilla). An attacker with a valid AD account can register a duplicate or conflicting Service Principal Name (SPN) in the AD forest and then request a TGS ticket impersonating a higher-privileged FreeIPA client, which FreeIPA services accept without challenge. The attack is network-based, requires low privileges (a valid AD account), no user interaction, and has a changed scope because the impact crosses from the AD realm into the FreeIPA domain. Exploitation is constrained by the requirement for a cross-realm trust to be established and the ability to register a conflicting SPN — a prerequisite that Microsoft mitigated on Windows Server 2012 R2 (with MSKB-3070083) and by default on Windows 11 22H2 and later (Red Hat CVE).
Successful exploitation allows an authenticated but low-privileged Active Directory user to impersonate higher-privileged FreeIPA accounts, gaining unauthorized access to the FreeIPA web portal, SMB file shares, and LDAP directory with the privileges of the impersonated account (Red Hat CVE). This results in high confidentiality and integrity impact — an attacker could read sensitive directory data, modify LDAP entries, access shared files, and escalate to administrative roles within the FreeIPA domain. Availability is not directly impacted. The scope change means a compromise originating in the AD realm can fully compromise the FreeIPA domain, enabling lateral movement across the hybrid identity infrastructure (GitHub Advisory).
As of the disclosure date (August 20, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is reported as 0.0, and NVD SSVC data indicates exploitation is currently assessed as "none" and the attack is not automatable ([Feedly Intelligence]). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Red Hat rates the practical exploitability as constrained because it requires an established FreeIPA–AD trust, a valid AD account, and the ability to register a conflicting SPN — conditions blocked in environments running patched, modern Windows domain controllers (Red Hat CVE).
kinit with the AD account, then craft a TGS-REQ) to request a service ticket for a FreeIPA service, supplying a cname field that impersonates a higher-privileged FreeIPA user rather than the actual AD account identity.cname field that does not match the authenticating AD account identity; cross-realm ticket requests for FreeIPA services from unexpected AD accounts.A patch is available from Red Hat; organizations should apply the relevant FreeIPA/IPA package updates for their Red Hat Enterprise Linux version as soon as possible (Red Hat CVE, Red Hat Bugzilla). Red Hat notes that no configuration-based mitigation fully meets their deployment criteria, so patching is the primary remediation. As interim measures, restrict network access to FreeIPA services (portal, LDAP, SMB) from AD users, or disable the FreeIPA–AD cross-realm trust if it is not actively required. Ensure all Active Directory domain controllers are running Windows Server 2012 R2 or later with MSKB-3070083 applied (or Windows 11 22H2+), which blocks the SPN registration prerequisite on the AD side (Red Hat CVE). Monitor FreeIPA service access logs for authentication anomalies from AD users as a detective control.
The vulnerability was reported by researcher Vladislav Plyatsok (rd01f) and acknowledged by Red Hat Product Security (Red Hat CVE). Red Hat notably rated the vulnerability as "Moderate" severity internally despite the 9.6 Critical CVSS score, citing that practical exploitation is significantly constrained in modern, patched environments — a nuanced position that highlights the gap between theoretical CVSS scoring and real-world exploitability. Coverage appeared on The Hacker Wire and various vulnerability aggregators shortly after disclosure, reflecting standard community interest in high-CVSS identity infrastructure vulnerabilities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."