CVEFinder.io

CVE-2026-11861

⛔ critical
🔍 Scan for this CVE
Summary

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privi

Description

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.

CVSS Score
9.6
Critical
EPSS Score
0.2
Exploit Probability
Published Date
2026-08-20
First Seen: 2026-08-21
📊 Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.1% of all 350,976 vulnerabilities in our database.

#34,632
Top 10% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Aug 20, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
🏆 Discovered By
Red Hat would like to thank Vladislav Plyatsok (rd01f) for reporting this issue.
SSVC data provided by CISA
Last Modified 2026-08-24
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CWE IDs (Weakness Types)

📦 Affected Products 5

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-13097 ⚠️ high 8.7 0.3 A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attribut... 2026-08-20
CVE-2026-73196 🔶 medium 4.3 0.2 A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize... 2026-08-20
CVE-2026-73197 ⚠️ high 7.5 0.3 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form... 2026-08-20
CVE-2026-73198 ⚠️ high 7.5 0.3 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` ... 2026-08-20
CVE-2026-19617 🔶 medium 5.5 0.1 A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration ... 2026-08-14
CVE-2026-58224 🔶 medium 6.5 0.3 A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of rec... 2026-08-14
These CVEs affect the same products