OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-104047

MEDIUM · CVSS 5.3 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability exists in Microsoft’s SSSD when integrated with Microsoft Entra ID, where unsanitized search inputs can lead to unauthorized information disclosure through manipulated directory query filters. Local users can exploit this flaw by crafting specific lookup requests, potentially exposing sensitive data. Organizations using SSSD with Microsoft Entra ID should prioritize patching to mitigate the risk of data leakage.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104047
Severity
MEDIUM
CVSS
5.3
EPSS
0.11%
Microsoft

Original NVD Description

A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)