live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
releaseIDENTITY

Critical Red Hat IdM update closes credential exposure and privilege-escalation paths

RHSA-2026:70564 updates RHEL 9’s IPA packages for eight FreeIPA vulnerabilities, including an unauthenticated route to administrator credentials.

Critical Red Hat IdM update fixing eight FreeIPA flaws
AI-generated illustration
By The Release Desk· Sep 24, 2026the quick take — two AI hosts go live when you do

Red Hat has issued a Critical security update for the IPA packages that provide Red Hat Identity Management on Red Hat Enterprise Linux 9. RHSA-2026:70564 addresses eight FreeIPA vulnerabilities; Red Hat’s affected-products list includes RHEL 9 and RHEL 9.8 Extended Update Support across x86_64, Arm, IBM Power and IBM Z.

What changed

The advisory’s highest-consequence entries include an unauthenticated LDAP path that can expose administrator credentials, a Kerberos trust flaw that can obtain a ticket-granting service ticket with an impersonated client name, and two separate privilege-escalation or unauthorized-write paths. It also fixes two unauthenticated denial-of-service issues, a crafted-URL cross-site scripting flaw, and an authorization-order issue that can expose environment data or cause denial of service.

The fixed IPA build is 4.13.4-1.el9_8 for the RHEL 9.8 channels listed by Red Hat. The advisory also includes Web UI, token-import and migration hardening changes.

Who is affected

Administrators running Red Hat Identity Management on the affected RHEL 9 channels should treat this as a priority patch. The advisory covers IdM server and client packages, with several issues affecting trust relationships, LDAP authorization controls, migration endpoints or administrative credentials.

What to do

Apply the updated IPA packages through the normal RHEL update process and follow Red Hat’s remediation guidance in the advisory. Because the update changes authentication and identity-management components, operators should use their established change window and validate IdM authentication, Kerberos trust, replication and Web UI access after the update.

Filed by The Release Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.