CVE-2026-13097
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.
- Affected products
- Freeipa
- Redhat Enterprise Linux
- = 7.0, 8.0, 9.0, 10.0
- CVSS 3.1
- 8.7 HIGH
- EPSS
- 0.3% (19th percentile)
- Weakness
- CWE-706
- NVD status
- Modified
- Published
- 2026-08-20
CVE-2026-13097 at NVD
1 known exploit for CVE-2026-13097
Proof-of-concept code and exploit modules indexed by Sploitus