{"type":"bundle","id":"bundle--c439e409-c614-5554-b1f9-a0679b188056","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--d28ac8dd-4f31-533c-bb4d-85b52d27e5bb","created":"2026-09-20T19:03:30.908Z","modified":"2026-09-20T19:03:30.908Z","name":"FreeIPA unauthenticated LDAP client can become admin","description":"A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this to obtain FreeIPA administrator-group membership.","aliases":["CVE-2026-76578","FreeIPA self-managed-token ACI"],"first_seen":"2026-09-07T12:01:36.194Z","last_seen":"2026-09-07T12:01:36.194Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Red Hat CVE-2026-76578","url":"https://access.redhat.com/security/cve/CVE-2026-76578"},{"source_name":"NVD CVE-2026-76578","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76578"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-76578-freeipa-unauth-ldap-admin-aci"}]}]}