CVE-2026-14476Disclosure

LOWCVSS 8.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-07-07); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-07-07: 3Mentions · 2026-07-08: 1Mentions · 2026-07-21: 1Patch / Workaround · 2026-07-21: 1Technical Details · 2026-07-07: 3Technical Details · 2026-07-08: 1Technical Details · 2026-07-21: 107-0707-0807-21
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-073
Disclosure3
2026-07-081
Disclosure1
2026-07-211
Patch1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-14476 A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attr… https://www.cve.org/CVERecord?id=CVE-2026-14476

    Post summary

    A path traversal vulnerability was discovered in SSSD's AD GPO provider (CVE‑2026‑14476), where the ad_gpo_extract_smb_components() function does not sanitize '..' sequences in the gPCFileSysPath LDAP attribute.

    00020996
    58.1K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 ALERTA: #openSUSE 2026-3139-1 corrige 2 falhas CRÍTICAS no SSSD (CVE-2026-14474 e CVE-2026-14476). Escalonamento de privilégio e bypass de autenticação podem comprometer TODOS os seus servidores. Saiba mais . -> http://tinyurl.com/3njc8jw3 https://t.co/nr1h3QCtKY

    Post summary

    The tweet announces that openSUSE’s 2026-3139-1 update patchively addresses two critical SSSD flaws (CVE-2026-14474 and CVE-2026-14476) involving privilege escalation and authentication bypass, and provides a link for further details.

    1000092
    1.5K followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-14476 (CVSS 8.0) Path traversal flaw in SSSD's AD GPO provider allows attackers with AD GPO access to write files as root, potentially bypassing authentication via Kerberos config injection. Affected: SSSD AD GPO provider https://t.co/FeecYoHMbN

    Post summary

    The tweet announces the high‑severity CVE‑2026‑14476, detailing a path‑traversal flaw in SSSD’s AD GPO provider that permits attackers to write files as root and potentially bypass Kerberos authentication.

    0000050
    68 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - SSSD AD GPO provider path traversal via gPCFileSysPath (CVE-2026-14476) A path traversal flaw in SSSD’s Active Directory GPO provider affects ad_gpo_extract_smb_components(), which parses the gPCFileSysPath LDAP attribute when fetching policy content. The root cause is improper input validation allowing “..” sequences to slip through and escape the intended GPO cache directory. An attacker with AD GPO management rights can craft a malicious gPCFileSysPath so the SSSD host writes attacker-controlled files as root outside the cache during GPO processing. Impact ranges from arbitrary root file write to Kerberos configuration injection and potential authentication bypass on default RHEL deployments even with SELinux enforcing. 👉 Affected: sssd, rhcos (versions not specified) | No fix yet — treat as suspicious

    Post summary

    The post announces a path traversal vulnerability in SSSD’s AD GPO provider (CVE-2026-14476), detailing how malicious gPCFileSysPath values can enable arbitrary root file writes and possible authentication bypass, with no patch or exploit provided.

    0000098
    243 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14476 A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attr… https://www.cve.org/CVERecord?id=CVE-2026-14476 ----- Traducción: CVE-2026-14476 Se … http://infoflow.cloud`

    Post summary

    The post announces a path traversal vulnerability (CVE-2026-14476) in SSSD's AD GPO provider, describing the affected function and linking to the official CVE record.

    0000035
    91 followersView on X

Explore more