Impact
The flaw allows an authenticated user from a trusted domain who shares the same username as a local account to bypass host‑based access control policies in SSSD. By stripping domain qualifiers, SSSD compares only short usernames and fails to detect the domain difference.
Affected Systems
Red Hat Enterprise Linux 6 through 10 and Red Hat OpenShift Container Platform 4 are affected, as all these systems run the vulnerable SSSD component. No specific version numbers are listed in the advisory.
Risk and Exploitability
The CVSS score is 6.8, indicating moderate severity. EPSS is not available and the vulnerability is not listed in KEV. Exploitation requires that an attacker first authenticates as a user in a trusted domain and then targets a host where a username collision exists. Once the bypass is achieved, the attacker can gain unauthorized access to any protected services or hosts governed by HBAC.
OpenCVE Enrichment