ID:12141 - Exploit for Input validation error in FreeIPA - CVE-2025-4404
Published: November 28, 2025
FreeIPA
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to application fails to validate the uniqueness of the "krbCanonicalName" for the admin account by default. A remote user can create services with the same canonical name as the REALM admin and retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential.