{"id":"CVE-2026-104047","title":"A flaw was found in SSSD","summary":"A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted loo…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-140"],"vendor":"Red Hat","product":"sssd","affected":["sssd (all versions)","sssd","sssd (all versions)","sssd (all versions)","sssd (all versions)","openshift/ose-rhel-coreos-8 (all versions)","openshift/ose-rhel-coreos-9 (all versions)"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T20:17:14.823","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104047","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104047","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2478616","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-06T19:46:03.994568Z"},"ingestedAt":"2026-10-06T20:16:42.481Z","slug":"CVE-2026-104047","body":"## Overview\n\nA flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}