Description
A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid credentials for an expired account can exploit this flaw to bypass access controls and authenticate to the system. This allows unauthorized access to persist after the account was intended to be deactivated.
Published: 2026-10-06
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access via Account Expiration Bypass
Action: Apply Patch
AI Analysis

Impact

SSSD fails to treat an LDAP shadow expiration value of zero as an expired account, allowing a user who can present valid credentials for such an account to authenticate successfully. The weakness is an improper sign conversion (CWE-193) that permits bypass of access controls and persists unauthorized access after an account should be deactivated.

Affected Systems

Red Hat Enterprise Linux 6, 7, 8, 9, 10 and Red Hat OpenShift Container Platform 4 are affected; specific impacted versions are not enumerated in the advisory.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. EPSS is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by authenticating with a valid credential set tied to an LDAP account whose expiration attribute is set to zero, thereby bypassing the intended deactivation. The attack can be carried out over the network if LDAP credentials are available, and does not require privilege escalation beyond the granted account rights.

Generated by OpenCVE AI on October 6, 2026 at 01:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor security update that fixes the SSSD LDAP expiration bug.
  • After updating, ensure that the LDAP shadow expiration policy is correctly enforced in SSSD and that accounts with a zero expiration value are treated as expired.
  • Review existing LDAP accounts for a zero expiration attribute and disable or adjust them until the patch is applied.

Generated by OpenCVE AI on October 6, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid credentials for an expired account can exploit this flaw to bypass access controls and authenticate to the system. This allows unauthorized access to persist after the account was intended to be deactivated.
Title Sssd: sssd: access control bypass via improper ldap shadow expiration check
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-193
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T00:12:16.731Z

Reserved: 2026-10-01T17:21:11.078Z

Link: CVE-2026-104033

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T01:16:34.143

Modified: 2026-10-06T01:16:34.143

Link: CVE-2026-104033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T01:30:09Z

Weaknesses