Sploitus

CVE-2026-13097

1 known exploit for CVE-2026-13097

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.

Affected products
Freeipa
Redhat Enterprise Linux
= 7.0, 8.0, 9.0, 10.0
CVSS 3.1
8.7 HIGH
EPSS
0.3% (19th percentile)
Weakness
CWE-706
NVD status
Modified
Published
2026-08-20
CVE-2026-13097 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-13097

Proof-of-concept code and exploit modules indexed by Sploitus