CVE-2026-92821
Received Received - Intake

SSSD LDAP Password Expiration Bypass via Early Rule Termination

Vulnerability report for CVE-2026-92821, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an expired-password warning terminates rule evaluation early and treats the access request as successful. A remote authenticated user with an expired password using an alternative authentication method, such as SSH public key authentication, can exploit this flaw to bypass access control restrictions and gain unauthorized access to protected systems.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat sssd 2.12.0-1.el10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-393 A function or operation returns an incorrect return value or status code that does not indicate the true result of execution, causing the product to modify its behavior based on the incorrect result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SSSD occurs when password expiration warnings are checked before restrictive access rules in LDAP setups. An expired password warning incorrectly terminates rule evaluation early, treating the access request as successful. This allows a remote authenticated user with an expired password but using an alternative authentication method like SSH public key login to bypass access controls and gain unauthorized access.

Detection Guidance

Check SSSD configuration for the ldap_access_order setting. Look for pwd_expire_policy_warn placed before restrictive rules like filter, host, or rhost. Use commands like grep -r 'ldap_access_order' /etc/sssd/ to inspect configurations.

Impact Analysis

If exploited, this vulnerability could allow unauthorized access to protected systems even with an expired password. Attackers could bypass access restrictions and gain entry using alternative authentication methods. The impact includes potential confidentiality and integrity breaches, depending on the compromised system's role.

Compliance Impact

This vulnerability could lead to unauthorized access, violating compliance requirements for access control and data protection in standards like GDPR and HIPAA. Unauthorized access may result in data breaches, non-compliance penalties, and reputational damage due to compromised confidentiality and integrity of sensitive information.

Mitigation Strategies

Modify the ldap_access_order in SSSD config to place pwd_expire_policy_warn after restrictive rules or replace it with pwd_expire_policy_reject. Avoid placing pwd_expire_policy_warn before filter, host, or rhost entries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92821. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart