SSSD Vulnerability in Trust-Enabled Identity Management Systems by Red Hat
CVE-2026-104048
6.8MEDIUM
What is CVE-2026-104048?
A vulnerability exists in SSSD affecting trust-enabled identity management environments. The flaw arises when SSSD evaluates Host-Based Access Control (HBAC) rules, which involves stripping domain qualifiers and comparing only short usernames. This design oversight enables authenticated users in a trusted domain who have the same username as a local account to bypass established access policies, potentially granting them unauthorized access to sensitive services or hosts.
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.