---
id: CVE-2026-104040
title: 'Sssd: sssd: information disclosure via odata injection in entra id lookups'
summary: >-
  A flaw was found in SSSD. When configured with the Entra ID identity provider,
  input lookup names containing single quotes are not properly escaped before
  being included in Microsoft Graph Open Data Protocol (OData) queries. A
  low-privil…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'
cvssSource: cna
cwe:
  - CWE-140
vendor: Red Hat
product: sssd
affected:
  - sssd (all versions)
  - sssd
  - sssd (all versions)
  - sssd (all versions)
  - sssd (all versions)
  - openshift/ose-rhel-coreos-8 (all versions)
  - openshift/ose-rhel-coreos-9 (all versions)
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T01:00:44.515Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-104040'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-104040'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2478915'
    label: RHBZ#2478915
tags:
  - cve.org
ingestedAt: '2026-10-06T01:38:44.803Z'
---

## Overview

A flaw was found in SSSD. When configured with the Entra ID identity provider, input lookup names containing single quotes are not properly escaped before being included in Microsoft Graph Open Data Protocol (OData) queries. A low-privileged local user can exploit this flaw by submitting a crafted search request, altering query filters to broaden user or group searches. This can lead to information disclosure by retrieving unintended directory objects, as well as a Denial of Service (DoS) through excessive processing and cache population.

## Affected

- `sssd (all versions)`
- `sssd`
- `sssd (all versions)`
- `sssd (all versions)`
- `sssd (all versions)`
- `openshift/ose-rhel-coreos-8 (all versions)`
- `openshift/ose-rhel-coreos-9 (all versions)`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
