RHSA-2026:41937HighCVSS 8.8

Red Hat Security Advisory: sssd security update

Published
July 20, 2026
Last Modified
July 20, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-14474 — sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation CVE-2026-14476 — sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass

🔗 References (5)