Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-87853

5 дней назад

(A flaw was found in SSSD's IdP authentication provider. The eval_acces ...)

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-87853

7 дней назад

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-87853

7 дней назад

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-87853

7 дней назад

A flaw was found in SSSD's IdP authentication provider. The eval_acces ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-993g-jgf7-rg3x

6 дней назад

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-87853

(A flaw was found in SSSD's IdP authentication provider. The eval_acces ...)

CVSS3: 7.5
0%
Низкий
5 дней назад
redhat логотип
CVE-2026-87853

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.

CVSS3: 7.5
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-87853

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.

CVSS3: 7.5
0%
Низкий
7 дней назад
debian логотип
CVE-2026-87853

A flaw was found in SSSD's IdP authentication provider. The eval_acces ...

CVSS3: 7.5
0%
Низкий
7 дней назад
github логотип
GHSA-993g-jgf7-rg3x

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.

CVSS3: 7.5
0%
Низкий
6 дней назад

Уязвимостей на страницу