security1 publisher
An unauthenticated LDAP client can write itself into FreeIPA's administrators group
CVE-2026-76578 pairs a default FreeIPA access rule with a 389 Directory Server ownership check that an empty name satisfies, and Red Hat says it reproduced the chain twice on a stock install. The fix is 4.13.4.
Publishers:thehackernews.com
Reality
- Evidence76
- Adoption30
- Hype gap+15
- Incentives58