{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/system-security-services-daemon/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sssd:sssd:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-87853"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["System Security Services Daemon"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SSSD"],"content_html":"\u003cp\u003eA vulnerability exists within the System Security Services Daemon (SSSD) IdP authentication provider, specifically located in the \u003ccode\u003eeval_access_token_buf()\u003c/code\u003e function. The flaw stems from an improper implementation of identifier validation using \u003ccode\u003estrncmp()\u003c/code\u003e. Instead of performing an exact string comparison between the OIDC subject identifier and the authenticated user's identifier, the function performs a prefix comparison.\u003c/p\u003e\n\u003cp\u003eThis logic error enables an attacker to gain unauthorized access to an account if their own IdP identifier matches the initial characters of a target user's identifier. For example, an attacker with an identifier of \u0026quot;user\u0026quot; could potentially authenticate as \u0026quot;username\u0026quot;. This issue poses a significant risk to organizations relying on SSSD for federated authentication, as it effectively allows for identity spoofing without requiring knowledge of a password or secondary factors, provided the attacker can control or influence their own identifier within the configured IdP.\u003c/p\u003e\n","date_modified":"2026-09-10T03:03:44Z","date_published":"2026-09-10T03:03:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sssd-auth-bypass/","summary":"A vulnerability in the SSSD IdP authentication provider allows an attacker to impersonate a target user if their IdP identifier is a prefix of the victim's identifier.","title":"Authentication Bypass Vulnerability in SSSD IdP Provider","url":"https://feed.craftedsignal.io/briefs/2026-09-sssd-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - System Security Services Daemon","version":"https://jsonfeed.org/version/1.1"}