AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-11861

CRITICAL · CVSS 9.6 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-08-25

CyberRota Analysis

AI-Generated

A critical vulnerability in FreeIPA allows authenticated Active Directory users to bypass authentication for FreeIPA services, such as the portal, SMB server, and LDAP directory, by impersonating a client name in the Ticket Granting Service (TGS). This occurs due to the lack of verification for Privilege Attribute Certificate (PAC) certificates, enabling privilege escalation within the FreeIPA domain. Organizations using FreeIPA in conjunction with Active Directory should prioritize immediate remediation to mitigate the risk of unauthorized access and privilege escalation.

CVE
CVE-2026-11861
Severity
CRITICAL
CVSS
9.6
EPSS
0.20%

Original NVD Description

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.

Related CVEs

Other vulnerabilities affecting the same vendor(s)