Junglewise Threat Intelligence

CVE-2026-14474: Red Hat SSSD privilege escalation in LDAP sudo provider

CVE-2026-14474 · Severity: high · CVSS 8.8 · Published 2026-07-07

Vendors: Red Hat.

Executive brief

A security flaw exists in the System Security Services Daemon (SSSD), a service used to manage access to Linux systems via centralized identity providers like LDAP. When not specifically configured, the service searches the entire corporate directory for administrative (sudo) rules rather than a restricted area. This allows an attacker who has permission to edit even a small, unrelated part of the directory to grant themselves full administrative control over every server connected to that directory.

Technical details

A vulnerability classified as Insecure Default Initialization (CWE-1188) exists in SSSD's LDAP sudo provider. When the 'ldap_sudo_search_base' option is not explicitly defined, SSSD defaults to the domain's root DN and performs a SUBTREE scope search for 'sudoRole' objects across the entire LDAP directory. An authenticated attacker with write access to any portion of the LDAP tree can inject a malicious sudoRole object. Because SSSD processes these objects globally by default, the attacker can grant themselves root-level sudo privileges on all hosts enrolled via SSSD. This affects 'sudo_provider = ldap' and 'sudo_provider = ad' configurations, while 'ipa' is unaffected.

Affected products

  • Red Hat SSSD Red Hat Enterprise Linux 7, 8, 9, 10; OpenShift Container Platform 4

Timeline

  • 2026-07-07: advisory: Initial publication of CVE-2026-14474 by Red Hat and NVD.

References