云虫漏洞情报

CVE-2026-13097 - A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resultin - 漏洞详情

漏洞编号:CVE-2026-13097

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-13097

CNNVD 编号:-

厂商/产品:redhat / enterprise_linux

影响范围:cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

CWE:CWE-706

发布/更新时间:2026-08-20 / 2026-08-27

漏洞描述

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.

相关链接

相关漏洞

« 返回首页