Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-104048

A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 18.4%
CVSS Severity
CVSS v3 Score 6.8


Contact Us

Shodan ® - All rights reserved