Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14474

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 8.8

Описание

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

Отчет

Red Hat has rated this as Important because the attack requires only low-privilege delegated LDAP write access to any subtree, which is a common delegation pattern in enterprise environments. The default ldap_sudo_search_base configuration searches the entire directory tree, allowing sudo rule injection from outside the intended sudoers container.

Меры по смягчению последствий

Set ldap_sudo_search_base explicitly in /etc/sssd/sssd.conf to restrict the search to the designated sudoers container: [domain/example.com] ldap_sudo_search_base = ou=sudoers,dc=example,dc=com Additionally, restrict LDAP ACLs to prevent non-admin principals from creating sudoRole objects outside the designated sudoers container.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sssdOut of support scope
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected
Red Hat Enterprise Linux 10sssdFixedRHSA-2026:4193720.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportsssdFixedRHSA-2026:4648227.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportsssdFixedRHSA-2026:5010904.08.2026
Red Hat Enterprise Linux 8sssdFixedRHSA-2026:4699028.07.2026
Red Hat Enterprise Linux 8sssdFixedRHSA-2026:4699028.07.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportsssdFixedRHSA-2026:4984104.08.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnsssdFixedRHSA-2026:4984104.08.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportsssdFixedRHSA-2026:4984404.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1188
https://bugzilla.redhat.com/show_bug.cgi?id=2496556sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
nvd
3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
debian
3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_sear ...

CVSS3: 8.8
github
3 месяца назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

suse-cvrf
2 месяца назад

Security update for sssd

8.8 High

CVSS3