OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-104048

MEDIUM · CVSS 6.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in SSSD allows authenticated users from trusted domains to bypass Host-Based Access Control (HBAC) rules by using short usernames that match those of authorized local accounts. This flaw can lead to unauthorized access to protected services or hosts, posing a risk to identity management environments. Organizations utilizing SSSD in trust-enabled setups should prioritize addressing this issue to mitigate potential security breaches.

CVE
CVE-2026-104048
Severity
MEDIUM
CVSS
6.8
EPSS
0.28%

Original NVD Description

A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts.

Related CVEs

Other vulnerabilities affecting the same vendor(s)