Skip to content
VulniPulse
Advisory severityMedium6.8Red Hat Linux

Medium [CVE-2026-92821] Sssd: sssd: access control bypass via premature ldap access rule evaluation

This medium-severity Red Hat Linux advisory covers CVE-2026-92821 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-92821 Source published Source updated

VulniPulse record published

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an expired-password warning terminates rule evaluation early and treats the access request as successful.

A remote authenticated user with an expired password using an alternative authentication method, such as SSH public key authentication, can exploit this flaw to bypass access control restrictions and gain unauthorized access to protected systems.

This vulnerability is rated as Moderate severity because successful exploitation requires a specific non-default configuration where `pwd_expire_policy_warn` is ordered ahead of restrictive rules in `ldap_access_order`, combined with a valid user account possessing an expired password.

In default Red Hat Enterprise Linux configurations, this access evaluation sequence is not configured, which minimizes typical exposure.

While the flaw permits an authenticated user to bypass host or filter restrictions using alternate authentication methods such as SSH public keys, the prerequisites prevent remote, unauthenticated access or compromise in standard installations. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).

Weakness: CWE-393.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Mitigation checklist

Temporary workarounds
  • To mitigate this issue without applying package fixes, reconfigure SSSD access ordering so that password expiration warnings do not precede restrictive access rules. 1. Modify `/etc/sssd/sssd.conf` in the relevant domain section: - Place `pwd_expire_policy_warn` after restrictive rules in `ldap_access_order` (e.g., change `ldap_access_order = pwd_expire_policy_warn, filter, host` to `ldap_access_order = filter, host, pwd_expire_policy_warn`). - Alternatively, replace `pwd_expire_policy_warn` with `pwd_expire_policy_reject` if expired accounts must not proceed through subsequent checks. 2. Restart the SSSD service to apply the configuration: ``` systemctl restart sssd ``` Warning: Restarting SSSD causes a brief disruption to active authentication requests and identity lookups. Additionally, altering access rules or switching to `pwd_expire_policy_reject` may alter user access behavior by immediately denying accounts with expired credentials.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.