CVE-2026-11861Disclosure(freeipa / enterprise_linux)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freeipa enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • freeipa

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
enterprise_linuxfreeipa

4 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-20: 2Mentions · 2026-08-21: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-20: 208-2008-21
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-202
Disclosure1Patch1
2026-08-211
General1
Full discourse3 posts
  • SecureShield@SecureShield_
    General

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-11861 参照元(ベンダー等): https://access.redhat.com/security/cve/CVE-2026-11861, https://bugzilla.redhat.com/show_bug.cgi?id=2487472

    Post summary

    The post simply lists the CVE identifiers and links to NVD and vendor advisories, without any additional technical or operational details.

    0000030
    26 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - FreeIPA Authentication Bypass via Kerberos PAC Impersonation Across AD Trust (CVE-2026-11861) In FreeIPA (Red Hat IdM) deployments with an Active Directory trust configured, an authenticated AD user can bypass authentication for FreeIPA services, the web portal, SMB server, and LDAP directory, by impersonating a client name in the Kerberos TGS. The root cause is that FreeIPA services do not verify the Privilege Attribute Certificate (PAC). The result is privilege escalation across the AD-to-FreeIPA trust boundary, effectively a compromise of the identity domain. It needs a valid AD account and a configured trust. Affects the ipa package on RHEL 7-10; Red Hat notes no acceptable mitigation, so patching is the path. CVSS 9.6. 👉Apply the FreeIPA/ipa security update per the Red Hat advisory (CVE-2026-11861).

    Post summary

    The advisory announces a critical FreeIPA authentication bypass vulnerability (CVE-2026-11861) and urges users to apply the Red Hat security update, providing detailed technical information and the CVSS score but no exploit code or evidence of active exploitation.

    0000071
    292 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-11861 FreeIPA Authentication Bypass via PAC Impersonation in Trust Relationships https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-11861

    Post summary

    Announces CVE‑2026‑11861, a FreeIPA authentication bypass via PAC impersonation, with a link to a vulnerability detail page.

    00000104
    4.1K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appfreeipafreeipa---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more