Impact
SSSD’s LDAP sudo provider flaw causes the system to search the entire LDAP directory tree for sudoRole objects when the ldap_sudo_search_base option is not set. An authenticated attacker who can write to any subtree of the directory can inject a sudoRole object, granting that attacker root‑level sudo privileges on every host where SSSD is enrolled, thereby achieving full administrative control.
Affected Systems
The flaw affects all Red Hat Enterprise Linux releases from 6 to 10, including the 10.0 Extended Update Support track, as well as Red Hat OpenShift Container Platform 4. Any installation of SSSD in these environments that does not explicitly configure a sudo search base is vulnerable.
Risk and Exploitability
A CVSS score of 8.8 reflects high severity, while an EPSS score of < 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an LDAP account with write permissions; attackers who already hold such permissions can create or modify sudoRole entries, escalating privileges across all SSSD‑enabled hosts.
OpenCVE Enrichment