PT-2026-96814 · Sssd · Sssd

·

CVE-2026-90462

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SSSD (affected versions not specified)
Description A flaw exists when the software is configured with the LDAP access provider and the ldap access order variable includes ppolicy or lockout. A fail-open condition occurs during the LDAP ppolicy access check if a user lookup returns zero results. This leads to an incorrect success response and caches an allow decision, which enables continued authorization for users who have been deleted or deprovisioned. A remote attacker with prior valid account context can exploit this to maintain access to information and potentially make limited modifications to resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90462

Affected Products

Sssd