#VU116216 Insufficient Granularity of Access Control in FreeIPA - CVE-2025-7493
Published: October 1, 2025
FreeIPA
freeipa.org
Description
The vulnerability allows a remote user to escalate privileges from host to domain administrator.
The vulnerability exists due the application does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. A remote user can perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.