PT-2026-56171 · Sssd+2 · Sssd+2
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
sssd (affected versions not specified)
rhcos (affected versions not specified)
Description
A flaw exists in the SSSD LDAP sudo provider due to insecure default configuration and improper scoping of LDAP searches. When the
ldap sudo search base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any LDAP subtree can inject a crafted sudoRole object, allowing them to grant themselves root-level sudo privileges on all SSSD-enrolled hosts, potentially leading to full system compromise and lateral movement.Recommendations
Upgrade to a vendor-fixed version.
As a temporary mitigation, explicitly set the
ldap sudo search base option.Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Rhcos
Sssd