8.1

CVE-2026-104048

Exploit

Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation

A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Sssd Version 2.12.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.184
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
RedHat 6.8 1.6 5.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-1025 Comparison Using Wrong Factors

The code performs a comparison between two entities, but the comparison examines the wrong factors or characteristics of the entities, which can lead to incorrect results and resultant weaknesses.

https://access.redhat.com/security/cve/CVE-2026-104048
Vendor Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2478613
Vendor Advisory
Exploit
Issue Tracking
Mitigation