PatchSiren cyber security CVE debrief
CVE-2026-11861 Red Hat CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T11:16:19.270Z and has not been modified since then. This CVE-2026-11861 vulnerability involves FreeIPA and Active Directory trust relationships, allowing Active Directory users to bypass authentication for FreeIPA services like the portal, SMB server, and LDAP directory. The bypass occurs because FreeIPA services do not verify Privilege Attribute Certificate (PAC) certificates, enabling impersonation in the Ticket Granting Service (TGS). Consequently, authenticated Active Directory users can escalate privileges within the FreeIPA domain. To address this, defenders should verify and limit Active Directory user access to FreeIPA services, implement PAC certificate verification, monitor authentication attempts, and apply vendor patches.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-20
- Original CVE updated
- 2026-08-24
- Advisory published
- 2026-08-20
- Advisory updated
- 2026-08-24
Who should care
System administrators and security teams managing FreeIPA and Active Directory environments, as well as users with access to FreeIPA services, should be aware of this vulnerability. They should verify and limit Active Directory user access to FreeIPA services, implement Privilege Attribute Certificate (PAC) certificate verification for FreeIPA services, and monitor and audit authentication attempts for suspicious activity. Additionally, they should review and restrict access to sensitive FreeIPA resources and apply vendor patches and updates for FreeIPA as needed. This includes IT staff responsible for identity and access management, security operations, and compliance within affected organizations.
Technical summary
A flaw in FreeIPA allows Active Directory users to bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory, by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain. The issue arises from the lack of verification of PAC certificates in FreeIPA services, which can be exploited by authenticated Active Directory users.
Defensive priority
Authenticated Active Directory users may escalate privileges within the FreeIPA domain; verify and limit AD user access.
Recommended defensive actions
- Verify and limit Active Directory user access to FreeIPA services
- Implement Privilege Attribute Certificate (PAC) certificate verification for FreeIPA services
- Monitor and audit authentication attempts for suspicious activity
- Apply vendor patches and updates for FreeIPA
- Review and restrict access to sensitive FreeIPA resources
Evidence notes
The vulnerability allows Active Directory users to bypass authentication for FreeIPA services by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This issue arises from the lack of verification of PAC certificates in FreeIPA services, which can be exploited by authenticated Active Directory users to escalate their privileges within the FreeIPA domain. To verify and mitigate this vulnerability, defenders should review FreeIPA and Active Directory configurations, verify user access controls, and implement Privilege Attribute Certificate (PAC) certificate verification for FreeIPA services.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-11861 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-11861
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-11861 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11861
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-11861
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.