ID:12312 - Exploit for Input validation error in FreeIPA - CVE-2025-4404

 
Main Vulnerability Database Exploits ID:12312 - Exploit for Input validation error in FreeIPA - CVE-2025-4404

ID:12312 - Exploit for Input validation error in FreeIPA - CVE-2025-4404

Published: January 16, 2026


Vulnerability identifier: #VU112054
Vulnerability risk: Medium
CVE-ID: CVE-2025-4404
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Vulnerable software:
FreeIPA

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to application fails to validate the uniqueness of the "krbCanonicalName" for the admin account by default. A remote user can create services with the same canonical name as the REALM admin and retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. 


Remediation

Install updates from vendor's website.