Critical Red Hat IdM update closes credential exposure and privilege-escalation paths
RHSA-2026:70564 updates RHEL 9’s IPA packages for eight FreeIPA vulnerabilities, including an unauthenticated route to administrator credentials.
Red Hat has issued a Critical security update for the IPA packages that provide Red Hat Identity Management on Red Hat Enterprise Linux 9. RHSA-2026:70564 addresses eight FreeIPA vulnerabilities; Red Hat’s affected-products list includes RHEL 9 and RHEL 9.8 Extended Update Support across x86_64, Arm, IBM Power and IBM Z.
What changed
The advisory’s highest-consequence entries include an unauthenticated LDAP path that can expose administrator credentials, a Kerberos trust flaw that can obtain a ticket-granting service ticket with an impersonated client name, and two separate privilege-escalation or unauthorized-write paths. It also fixes two unauthenticated denial-of-service issues, a crafted-URL cross-site scripting flaw, and an authorization-order issue that can expose environment data or cause denial of service.
The fixed IPA build is 4.13.4-1.el9_8 for the RHEL 9.8 channels listed by Red Hat. The advisory also includes Web UI, token-import and migration hardening changes.
Who is affected
Administrators running Red Hat Identity Management on the affected RHEL 9 channels should treat this as a priority patch. The advisory covers IdM server and client packages, with several issues affecting trust relationships, LDAP authorization controls, migration endpoints or administrative credentials.
What to do
Apply the updated IPA packages through the normal RHEL update process and follow Red Hat’s remediation guidance in the advisory. Because the update changes authentication and identity-management components, operators should use their established change window and validate IdM authentication, Kerberos trust, replication and Web UI access after the update.
sources
comments · 0