CVE Database
/

CVE-2025-7493

Back to search

CVE-2025-7493

Published: Sep 30, 2025

Modified: Feb 26, 2026

PUBLISHED

CVSS v3.1

9.1

CRITICAL

Description

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

VendorProductVersions

Red Hat

Red Hat Enterprise Linux 10

unaffected
0:4.12.2-15.el10_0.4 - < *

Red Hat

Red Hat Enterprise Linux 7 Extended Lifecycle Support

unaffected
0:4.6.8-5.el7_9.23 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
8100020250919180242.143e9e98 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
8100020250918211722.823393f5 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Advanced Update Support

unaffected
8020020250924110056.50ea30f9 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Advanced Update Support

unaffected
8020020250924104944.792f4060 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

unaffected
8040020250923180004.f153676a - < *

Red Hat

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

unaffected
8040020250923175408.5b01ab7e - < *

Red Hat

Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

unaffected
8040020250923180004.f153676a - < *

Red Hat

Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

unaffected
8040020250923175408.5b01ab7e - < *

Red Hat

Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

unaffected
8060020250916172436.c1533a64 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

unaffected
8060020250916174421.ada582f1 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Telecommunications Update Service

unaffected
8060020250916172436.c1533a64 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Telecommunications Update Service

unaffected
8060020250916174421.ada582f1 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions

unaffected
8060020250916172436.c1533a64 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions

unaffected
8060020250916174421.ada582f1 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Telecommunications Update Service

unaffected
8080020250918184739.e581a9e4 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Telecommunications Update Service

unaffected
8080020250918152850.b0a6ceea - < *

Red Hat

Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

unaffected
8080020250918184739.e581a9e4 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

unaffected
8080020250918152850.b0a6ceea - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:4.12.2-14.el9_6.5 - < *

Red Hat

Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

unaffected
0:4.9.8-11.el9_0.5 - < *

Red Hat

Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

unaffected
0:4.10.1-12.el9_2.6 - < *

Red Hat

Red Hat Enterprise Linux 9.4 Extended Update Support

unaffected
0:4.11.0-15.el9_4.7 - < *

Red Hat

Red Hat Enterprise Linux 6

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

References

RHSA-2025:17084
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17085
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17086
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17087
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17088
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17129
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17645
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17646
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17647
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17648
vendor-advisory
x_refsource_REDHAT
RHSA-2025:17649
vendor-advisory
x_refsource_REDHAT
RHBZ#2389448
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now