CVE-2026-11861: Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships

Published Jun 10, 2026
·
Updated

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.

Other sources

If trust relationship between FreeIPA and Active Directory is configured (established/created), AD users can bypass authentication of the FreeIPA portal, SMB server, LDAP directory and, presumably, any other GSSAPI services unauthorized, using impersonation in TGS, under certain conditions. In the worst case scenario a user could escalate their priveleges (permissions/rights) in FreeIPA domain. This is due to the fact that the portal, like other GSSAPI services, is not configured to verify PAC certificates and trusts the TGS cname field.

Red Hat

Affected Software

6 affected components
FreeIPA FreeIPA
FreeIPA FreeIPA<4.13.3
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0

Event History

Jun 10, 2026
Data Sourced
via Red Hat·11:50 AM
DescriptionSeverityAffected Software
Aug 20, 2026
CVE Published
via MITRE·10:39 AM
Data Sourced
via MITRE·10:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments with an established trust relationship between FreeIPA and Active Directory are exposed. The affected FreeIPA services include the portal, SMB server, and LDAP directory, and other GSSAPI services may also be affected.

2

What level of access does an attacker need?

An attacker needs to be an authenticated Active Directory user in an environment where the Active Directory-FreeIPA trust is configured. They can exploit impersonation in Ticket Granting Service requests to bypass authentication for FreeIPA services and potentially escalate privileges in the FreeIPA domain.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203