RHSA-2026:49844HighCVSS 8.8

Red Hat Security Advisory: sssd security update

Published
August 4, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-14474 — sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation CVE-2026-14476 — sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass

🎯 Affected products180

  • Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libipa_hbac-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libipa_hbac-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libipa_hbac-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libipa_hbac-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libipa_hbac-debuginfo-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libipa_hbac-debuginfo-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libipa_hbac-debuginfo-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libipa_hbac-debuginfo-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_autofs-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_autofs-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_autofs-debuginfo-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_autofs-debuginfo-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_autofs-debuginfo-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_autofs-debuginfo-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_certmap-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_certmap-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_certmap-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_certmap-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_certmap-debuginfo-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_certmap-debuginfo-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_certmap-debuginfo-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_certmap-debuginfo-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_idmap-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_idmap-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_idmap-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_idmap-0:2.6.2-4.el8_6.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • libsss_idmap-debuginfo-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • libsss_idmap-debuginfo-0:2.6.2-4.el8_6.5.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • +150 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Set ldap_sudo_search_base explicitly in /etc/sssd/sssd.conf to restrict the search to the designated sudoers container: [domain/example.com] ldap_sudo_search_base = ou=sudoers,dc=example,dc=com Additionally, restrict LDAP ACLs to prevent non-admin principals from creating sudoRole objects outside the designated sudoers container. Workaround: Set ad_gpo_access_control = disabled in /etc/sssd/sssd.conf to disable GPO fetching entirely. Note that this removes GPO-based login policy enforcement.

🔗 References (5)