Signal is active with 1 mentions in latest observed window
Immediate actions
Patch freeipa enterprise_linux systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
🚨Critical - FreeIPA Authentication Bypass via Kerberos PAC Impersonation Across AD Trust (CVE-2026-11861)
In FreeIPA (Red Hat IdM) deployments with an Active Directory trust configured, an authenticated AD user can bypass authentication for FreeIPA services, the web portal, SMB server, and LDAP directory, by impersonating a client name in the Kerberos TGS. The root cause is that FreeIPA services do not verify the Privilege Attribute Certificate (PAC).
The result is privilege escalation across the AD-to-FreeIPA trust boundary, effectively a compromise of the identity domain. It needs a valid AD account and a configured trust. Affects the ipa package on RHEL 7-10; Red Hat notes no acceptable mitigation, so patching is the path. CVSS 9.6.
👉Apply the FreeIPA/ipa security update per the Red Hat advisory (CVE-2026-11861).
Post summary
The advisory announces a critical FreeIPA authentication bypass vulnerability (CVE-2026-11861) and urges users to apply the Red Hat security update, providing detailed technical information and the CVSS score but no exploit code or evidence of active exploitation.