在 FreeIPA 中发现了一个漏洞。当 FreeIPA 与 Active Directory(活动目录)配置信任关系时,Active Directory 用户可能绕过对 FreeIPA 服务(包括门户、SMB 服务器和 LDAP 目录)的身份验证。此问题是由于 FreeIPA 服务未验证特权属性证书(PAC)证书,攻击者可以通过在票据授予服务(TGS)中冒充客户端名称实现该绕过。该漏洞可能导致已认证的 Active Directory 用户在 FreeIPA 域内提升其权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67567 | 9.9 CRITICAL | Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart ap |
| CVE-2026-66788 | 9.9 CRITICAL | Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labels |
| CVE-2026-66785 | 9.9 CRITICAL | Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowe |
| CVE-2026-13097 | 9.1 CRITICAL | Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniquenes |
| CVE-2026-66787 | 8.7 HIGH | Lighthouse: lighthouse: cross-cluster dns spoofing via unvalidated endpointslice and servi |
| CVE-2026-77176 | 8.1 HIGH | Kata-containers: insufficient validation of createcontainer mount and storage rules in gen |
| CVE-2026-18917 | 7.8 HIGH | Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow |
| CVE-2026-19582 | 7.8 HIGH | Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe fi |
| CVE-2026-73137 | 7.7 HIGH | Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secr |
| CVE-2026-73198 | 7.5 HIGH | Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read |
| CVE-2026-73197 | 7.5 HIGH | Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request b |
| CVE-2026-19611 | 7.4 HIGH | Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: pass |
| CVE-2026-73199 | 6.5 MEDIUM | Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) |
| CVE-2026-77014 | 5.3 MEDIUM | Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of |
| CVE-2026-73196 | 4.3 MEDIUM | Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodi |
No comments yet