CVE-2026-13097
Last modified
CVE-2026-13097 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux | 10.0 |
| Freeipa | Freeipa | 4.12.2 |
References
- https://access.redhat.com/security/cve/CVE-2026-13097Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2515974Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-13097?
How severe is CVE-2026-13097?
How do I fix CVE-2026-13097?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13083A flaw was found in the Pen Drive report generator. Cluster-…6.9
- CVE-2026-13084A null pointer dereference vulnerability in WatchGuard Firew…7.5
- CVE-2026-13086A stack-based buffer overflow in the epm (Endpoint Protectio…9.3
- CVE-2026-13087A heap out-of-bounds write vulnerability was found in the Li…8.8
- CVE-2026-13089OIDC::Lite versions through 0.12.1 for Perl allow ID Token s…7.5
- CVE-2026-13094IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vu…7.8
- CVE-2026-1310The Simple calendar for Elementor plugin for WordPress is vu…5.3
- CVE-2026-13103A potential path traversal vulnerability was reported in Len…7.3
- CVE-2026-13104A potential vulnerability was reported in Lenovo App Store, …7.3
- CVE-2026-13105IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vu…8.8
- CVE-2026-13107IBM Business Automation Workflow containers and traditional …7.1
- CVE-2026-13108WatchGuard Dimension is susceptible to a denial-of-service c…8.7
Are you affected by CVE-2026-13097?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
