{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-942DAF1E",
  "slug": "cve-2026-76578-freeipa-unauth-ldap-admin-aci",
  "title": "FreeIPA unauthenticated LDAP client can become admin",
  "aliases": [
    "CVE-2026-76578",
    "FreeIPA self-managed-token ACI"
  ],
  "summary": "A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this to obtain FreeIPA administrator-group membership.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Confirm exact affected/fixed trains against the live Red Hat advisory for your install.",
  "firstObservedAt": "2026-09-07T12:01:36.194Z",
  "lastObservedAt": "2026-09-07T12:01:36.194Z",
  "publishedAt": "2026-09-20T19:03:30.908Z",
  "reviewedAt": "2026-09-20T19:03:20.186Z",
  "expiresAt": "2026-09-07T12:01:36.194Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "vendor",
      "label": "Red Hat CVE-2026-76578",
      "url": "https://access.redhat.com/security/cve/CVE-2026-76578",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-07T12:01:36.194Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-76578",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76578",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-07T12:01:36.194Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-76578-freeipa-unauth-ldap-admin-aci",
      "sourceType": "other_primary",
      "observedAt": "2026-09-07T12:01:36.194Z"
    }
  ],
  "artifacts": [
    {
      "id": "freeipa",
      "artifactClass": "package",
      "ecosystem": "redhat",
      "name": "FreeIPA",
      "version": null,
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-07T12:01:36.194Z",
      "eventType": "disclosure",
      "summary": "Red Hat disclosed CVE-2026-76578 FreeIPA unauth LDAP admin ACI.",
      "sourceIds": [
        "vendor",
        "nvd"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-07T14:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published operator blog coverage for CVE-2026-76578.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Campaign tracks CVE-2026-76578 only.",
    "Does not invent fixed versions beyond cited sources.",
    "HOL blog is operator guidance, not a substitute for the Red Hat advisory."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-76578-freeipa-unauth-ldap-admin-aci/corrections"
}
