Flaw in SSSD Affects LDAP Access for Red Hat Products
CVE-2026-90462

5.4MEDIUM

What is CVE-2026-90462?

A vulnerability exists in SSSD when configured to utilize the LDAP access provider with specific parameters. If a user lookup yields no results, a fail-open condition emerges in the LDAP ppolicy access check. This situation may trigger an inappropriate success response, allowing the system to cache this allowance. Consequently, a remote attacker who previously possessed valid account credentials could exploit this vulnerability, thereby retaining access to sensitive information and potentially making unauthorized alterations to resources that ought to be restricted.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.