{"id":"CVE-2026-104032","title":"A flaw was found in SSSD","summary":"A flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization checks. This triggers global cache invalidation and forces repeated lookup…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-408"],"vendor":"Red Hat","product":"sssd","affected":["sssd (all versions)","sssd","sssd (all versions)","sssd (all versions)","sssd (all versions)","openshift/ose-rhel-coreos-8 (all versions)","openshift/ose-rhel-coreos-9 (all versions)"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T01:16:33.997","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104032","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104032","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479381","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T00:37:36.245Z","slug":"CVE-2026-104032","body":"## Overview\n\nA flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization checks. This triggers global cache invalidation and forces repeated lookups to backend directory providers, leading to a Denial of Service (DoS) from degraded automount availability and elevated resource consumption.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}