#VU112054 Input validation error in FreeIPA - CVE-2025-4404
Published: June 30, 2025 / Updated: January 16, 2026
FreeIPA
freeipa.org
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to application fails to validate the uniqueness of the "krbCanonicalName" for the admin account by default. A remote user can create services with the same canonical name as the REALM admin and retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential.