CVE-2026-11861

Source
https://cve.org/CVERecord?id=CVE-2026-11861
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11861.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-11861
Downstream
Related
Published
2026-08-20T10:39:08.025Z
Modified
2026-09-02T22:10:54.690348988Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships
Details

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11861.json",
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-266"
    ]
}
References

Affected packages

Git / github.com/freeipa/freeipa

Affected ranges

Type
GIT
Repo
https://github.com/freeipa/freeipa
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.13.3"
        }
    ]
}

Affected versions

Other
alpha-1-9-0
alpha_1-4-2-0
alpha_1-4-4-0
alpha_2-1-9-0
alpha_3-1-9-0
alpha_4-1-9-0
alpha_5-1-9-0
alpha_5-1-9-0-1
beta_1-2-0-0
beta_1-3-0-0
beta_1-3-2-0
beta_1-3-3-0
beta_2-3-0-0
beta_2-3-3-0
milestone_2
milestone_3
milestone_4
milestone_4_1
milestone_6
rc_1-2-0-0
rc_2-2-0-0
rc_3-2-0-0
rc_4-7-0-1
rc_4-7-0-2
rc_4-8-0-1
rc_4-9-0-1
release-1-0-0
release-1-1-0
release-2-0-0
release-2-1-0
release-3-1-0
release-3-2-0
release-3-2-0-pre1
release-3-3-0
release-4-0-0
release-4-13-0
release-4-13-1
release-4-13-2
release-4-2-0
release-4-4-0
release-4-4-1
release-4-8-0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11861.json"