SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90995

MEDIUM · CVSS 5.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A vulnerability in the System Security Services Daemon (SSSD) allows local attackers with access to the PAM responder socket to exploit a NULL pointer dereference by sending a malformed protocol request, particularly when the `pam_app_services` configuration is enabled. This can result in a denial of service, causing the PAM responder to crash and interrupt authentication services. Organizations using SSSD with PAM should prioritize this issue to mitigate potential disruptions in authentication processes.

CVE
CVE-2026-90995
Severity
MEDIUM
CVSS
5.5
EPSS
N/A

Original NVD Description

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.