ThreatsTechnology, Cloud & SaaSCriticalFreeIPA LDAP ACI Vulnerability Chain Grants Anonymous Clients Domain Admin RightsRed Hat patched CVE-2026-76578 (CVSS 9.8) in FreeIPA and 389 Directory Server, where an LDAP Access Control Instruction flaw allowed unauthenticated clients to create permanent domain admins.Tom Verhoeven·8 Sep 2026, 14:45 IST·5 min read