Vendor
high
advisory
Authentication Bypass Vulnerability in SSSD IdP Provider
1 TTP 1 CVEA vulnerability in the SSSD IdP authentication provider allows an attacker to impersonate a target user if their IdP identifier is a prefix of the victim's identifier.
System Security Services Daemon
1t
1c
high
advisory
CVE-2026-14474 - SSSD LDAP sudo Provider Privilege Escalation
2 TTPs 1 CVEA vulnerability in SSSD's LDAP sudo provider, CVE-2026-14474, allows an authenticated attacker to achieve root-level privilege escalation by injecting a malicious sudoRole object into any writable LDAP subtree when the `ldap_sudo_search_base` option is not explicitly configured on SSSD-enrolled Linux hosts.
SSSD LDAP sudo provider
linux
privilege-escalation
cve
vulnerability
2t
1c