8.1
CVE-2026-104048
- EPSS 0.28%
- Veröffentlicht 06.10.2026 19:34:25
- Zuletzt bearbeitet 09.10.2026 12:54:42
- Erkennungen
Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation
A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Sssd Version 2.12.0
Redhat ≫ Openshift Container Platform Version 4.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.184 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
| RedHat | 6.8 | 1.6 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-1025 Comparison Using Wrong Factors
The code performs a comparison between two entities, but the comparison examines the wrong factors or characteristics of the entities, which can lead to incorrect results and resultant weaknesses.
https://access.redhat.com/security/cve/CVE-2026-104048
https://bugzilla.redhat.com/show_bug.cgi?id=2478613