Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 12 min 139 bronnen 4 kritiek 28 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-104048

MEDIUM · 6.8 CVSS Gepubliceerd: CWE-1025

Beschrijving

A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts.

References