SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90996

MEDIUM · CVSS 4

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A flaw in the System Security Services Daemon (SSSD) allows local unprivileged users to exploit the Network Security Services (NSS) responder by sending a specially crafted request with a zero-length body. This can result in a denial-of-service condition, leading to instability or termination of the NSS responder, impacting system availability. Organizations utilizing SSSD should prioritize addressing this vulnerability to maintain service reliability and prevent potential disruptions.

CVE
CVE-2026-90996
Severity
MEDIUM
CVSS
4
EPSS
N/A

Original NVD Description

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.