Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Freeipa

22 known vulnerabilities

2
CRITICAL
12
HIGH
4
MEDIUM

Top Products

freeipa 18
18 CVEs
7.5
CVE-2026-73198

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages`

7.5
CVE-2026-73197

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form

4.3
CVE-2026-73196

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize

8.7
CVE-2026-13097

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attribut

9.6
CVE-2026-11861

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Direct

8.2
CVE-2026-19550

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath

8.8
CVE-2019-14867

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before

6.5
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before

8.8
CVE-2012-5631

ipa 3.0 does not properly check server identity before sending credential containing cookies

4.4
CVE-2019-14826

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attack

8.1
CVE-2017-2590

A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the

6.3
CVE-2016-9575

Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modify

7.5
CVE-2017-12169

It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users'

8.8
CVE-2017-11191

FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions v

9.8
CVE-2015-5284

ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem,

7.5
CVE-2015-5179

FreeIPA might display user data improperly via vectors involving non-printable characters.

7.5
CVE-2016-7030

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows

7.5
CVE-2016-5414

FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.

Frequently Asked Questions

How many CVEs affect Freeipa?

Freeipa has 22 CVE records in our database, including 2 critical and 12 high severity vulnerabilities.

What are the most severe Freeipa vulnerabilities?

Freeipa has 2 critical severity (CVSS 9.0+) and 12 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Freeipa vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Freeipa products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Freeipa Vulnerabilities

CyberStrike scans your infrastructure for Freeipa vulnerabilities and provides real-time remediation guidance.

Get Started