PT-2026-56171 · Sssd+2 · Sssd+2

·

CVE-2026-14474

·

Published

2026-07-07

·

Updated

2026-09-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sssd (affected versions not specified) rhcos (affected versions not specified)
Description A flaw exists in the SSSD LDAP sudo provider due to insecure default configuration and improper scoping of LDAP searches. When the ldap sudo search base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any LDAP subtree can inject a crafted sudoRole object, allowing them to grant themselves root-level sudo privileges on all SSSD-enrolled hosts, potentially leading to full system compromise and lateral movement.
Recommendations Upgrade to a vendor-fixed version. As a temporary mitigation, explicitly set the ldap sudo search base option.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:41937
ALSA-2026:42122
ALSA-2026:46990
CVE-2026-14474
OESA-2026-3149
OESA-2026-3150
OESA-2026-3151
OESA-2026-3362
OESA-2026-3363
OPENSUSE-SU-2026:21290-1
RHSA-2026:41937
RHSA-2026:42122
RHSA-2026:46482
RHSA-2026:46990
RHSA-2026:49839
RHSA-2026:49840
RHSA-2026:49841
RHSA-2026:49842
RHSA-2026:49843
RHSA-2026:49844
RHSA-2026:50109
SUSE-SU-2026:22591-1
SUSE-SU-2026:22621-1
SUSE-SU-2026:22799-1
SUSE-SU-2026:22897-1
SUSE-SU-2026:3025-1
SUSE-SU-2026:3041-1
SUSE-SU-2026:3131-1
SUSE-SU-2026:3139-1
SUSE-SU-2026:3195-1

Affected Products

Rocky Linux
Rhcos
Sssd