CVE-2026-104040
Received Received - Intake

SSSD Entra ID Identity Provider OData Query Injection

Vulnerability report for CVE-2026-104040, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD. When configured with the Entra ID identity provider, input lookup names containing single quotes are not properly escaped before being included in Microsoft Graph Open Data Protocol (OData) queries. A low-privileged local user can exploit this flaw by submitting a crafted search request, altering query filters to broaden user or group searches. This can lead to information disclosure by retrieving unintended directory objects, as well as a Denial of Service (DoS) through excessive processing and cache population.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat sssd 2.12.0-1.el10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-140 The product does not neutralize or incorrectly neutralizes delimiters.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in SSSD when using the Entra ID identity provider for Microsoft Azure Active Directory lookups. It allows a low-privileged local attacker to inject single quotes into name-based lookups, manipulating OData queries sent to Microsoft Graph. This bypasses query constraints, broadening returned directory objects and causing unintended data exposure or excessive processing.

Detection Guidance

To detect this vulnerability, monitor SSSD logs for unusual OData query patterns or excessive data retrievals from Microsoft Graph. Check for name-based lookups containing single quotes in logs like /var/log/sssd/*.log. Look for queries with altered filter conditions such as startsWith(userPrincipalName,'a') or userPrincipalName ne ('@').

Commands to inspect: grep -r "entra_id_lookup" /var/log/sssd/ 2>/dev/null; journalctl -u sssd --no-pager | grep -i "odata\|filter". Ensure no untrusted users have access to trigger IdP-backed lookups.

Impact Analysis

The impact includes information disclosure by retrieving unintended directory objects and a Denial of Service through excessive processing and cache population. Exploitation requires local access and does not allow unauthorized modifications or privilege escalation.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, potentially violating GDPR or HIPAA compliance by disclosing sensitive directory objects. The risk depends on the permissions granted to the Graph client and the sensitivity of exposed data.

Mitigation Strategies

Immediately restrict local users from triggering Entra ID identity provider lookups. Disable the Entra ID IdP in SSSD configuration if not required. Review and minimize Microsoft Graph application permissions to reduce data exposure. Monitor system performance for unusual cache growth or high CPU usage.

Update SSSD to the latest patched version if available. Consider disabling name-based lookups via NSS for untrusted users until a fix is applied. Audit all SSSD configurations for the Entra ID IdP and remove or secure them.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104040. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart