Skip to content
cve — cve-2026-76578

grep -rl "CVE-2026-76578" ./articles

CVE-2026-76578

Two flaws in FreeIPA and 389 Directory Server are unremarkable on their own. Together they let an unauthenticated client write a token entry with blank ownership, satisfy the check for whether it owns that entry, and attach a Kerberos identity with administrative group membership. Nobody has published how to tell whether it already happened to you.

1 article — 2026-09-09

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

The anonymous client passes the ownership check by being nobody

2026-09-09Security

Two flaws in FreeIPA and 389 Directory Server are unremarkable on their own. Together they let an unauthenticated client write a token entry with blank ownership, satisfy the check for whether it owns that entry, and attach a Kerberos identity with administrative group membership. Nobody has published how to tell whether it already happened to you.

../cve — every identifier we have covered