CVE-2026-90462

MEDIUM Status: Awaiting Analysis

CVSS Scores

CVSS v3.x Base Score
5.4
MEDIUM

Description

A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued authorization for a deleted or deprovisioned user. A remote attacker with prior valid account context could exploit this to maintain access to information and potentially make limited modifications to resources that should no longer be available.

Published
September 22, 2026 4:18 PM
Last Modified
September 22, 2026 7:37 PM
Source
[email protected]

Weaknesses (CWE)

CWE-280

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.