Path Traversal Vulnerability in SSSD's Active Directory Group Policy Provider
CVE-2026-14476
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 7 July 2026
What is CVE-2026-14476?
A path traversal flaw exists in SSSD's Active Directory Group Policy (AD GPO) provider. Specifically, the ad_gpo_extract_smb_components() function fails to properly sanitize '..' sequences in the gPCFileSysPath LDAP attribute. This vulnerability enables an attacker with management access to the AD GPO to write files outside of the designated GPO cache directory, even with root privileges. In environments with default Red Hat Enterprise Linux (RHEL) configurations and SELinux enforced, this vulnerability could lead to the injection of malicious Kerberos configurations, ultimately resulting in authentication bypass.
Affected Version(s)
Red Hat Enterprise Linux 10 0:2.12.0-3.el10_2.1
Red Hat Enterprise Linux 10.0 Extended Update Support 0:2.10.2-3.el10_0.5
Red Hat Enterprise Linux 8 0:2.9.4-5.el8_10.5