Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14474

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

Отчет

Red Hat has rated this as Important because the attack requires only low-privilege delegated LDAP write access to any subtree, which is a common delegation pattern in enterprise environments. The default ldap_sudo_search_base configuration searches the entire directory tree, allowing sudo rule injection from outside the intended sudoers container.

Меры по смягчению последствий

Set ldap_sudo_search_base explicitly in /etc/sssd/sssd.conf to restrict the search to the designated sudoers container: [domain/example.com] ldap_sudo_search_base = ou=sudoers,dc=example,dc=com Additionally, restrict LDAP ACLs to prevent non-admin principals from creating sudoRole objects outside the designated sudoers container.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sssdOut of support scope
Red Hat Enterprise Linux 7sssdAffected
Red Hat Enterprise Linux 8sssdAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10sssdFixedRHSA-2026:4193720.07.2026
Red Hat Enterprise Linux 9sssdFixedRHSA-2026:4212220.07.2026
Red Hat Enterprise Linux 9sssdFixedRHSA-2026:4212220.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1188
https://bugzilla.redhat.com/show_bug.cgi?id=2496556sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation

EPSS

Процентиль: 34%
0.00415
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
nvd
24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS3: 8.8
debian
24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_sear ...

CVSS3: 8.8
github
24 дня назад

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

suse-cvrf
21 день назад

Security update for sssd

EPSS

Процентиль: 34%
0.00415
Низкий

8.8 High

CVSS3