DFIR Lab[verified]@DFIR_LabDisclosure
The tweet announces the high‑severity CVE‑2026‑14476, detailing a path‑traversal flaw in SSSD’s AD GPO provider that permits attackers to write files as root and potentially bypass Kerberos authentication.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces a path traversal vulnerability in SSSD’s AD GPO provider (CVE-2026-14476), detailing how malicious gPCFileSysPath values can enable arbitrary root file writes and possible authentication bypass, with no patch or exploit provided.
CVE@CVEnewDisclosure
A path traversal vulnerability was discovered in SSSD's AD GPO provider (CVE‑2026‑14476), where the ad_gpo_extract_smb_components() function does not sanitize '..' sequences in the gPCFileSysPath LDAP attribute.
Ferramentas Linux@Cezar_H_LinuxPatch
The tweet announces that openSUSE’s 2026-3139-1 update patchively addresses two critical SSSD flaws (CVE-2026-14474 and CVE-2026-14476) involving privilege escalation and authentication bypass, and provides a link for further details.
Infoflowcloud@infoflowcloudDisclosure
The post announces a path traversal vulnerability (CVE-2026-14476) in SSSD's AD GPO provider, describing the affected function and linking to the official CVE record.