CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-4404

Critical · CVSS 9.1

FreeIPA — Privilege escalation via krbCanonicalName uniqueness bypass (host to domain)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-1220

Description

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

Search profile — drives PoC discovery

Symbols krbCanonicalNameadmin@REALMkrbPrincipalNameipa service-addkrbCanonicalName uniquenessadmin accountKerberos ticketREALM adminservice principal
Keywords CVE-2025-4404FreeIPA privilege escalationkrbCanonicalName uniqueness bypassFreeIPA admin kerberos ticketFreeIPA host to domain escalationFreeIPA krbCanonicalName adminFreeIPA service canonical name collisionFreeIPA CWE-1220FreeIPA RHSA-2025:9184
Versions: Affected versions per RHSA-2025:9184 through RHSA-2025:9188 (multiple RHEL streams)

Ranked PoCs (4) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T12:00:22.000Z · profiled 2026-06-30T18:30:14.000Z