Exploit for CVE-2026-76578 CVE-2026-76560 CVE-2026-76578

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.

Published 7 Sep 2026Updated 8 Sep 20266 sources
CVSS 9.8 ✓ VERIFIED REFERENCE

Source timeline

Discovered through SploitusView source ↗
CVE record published by NVDView source ↗