A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD… (CVE-2026-104033)
Description
A vulnerability in SSSD allows bypassing account expiration enforcement when using LDAP shadow attributes. Specifically, SSSD does not treat an expiration value of zero as an expired account, permitting users with valid credentials for such accounts to authenticate despite intended deactivation. This flaw affects multiple specific versions of SSSD and has a medium severity rating.
CVSS v3.1
Score 5.4medium
Affected software
pkg:deb/ubuntu/sssd?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/sssd?arch=source&distro=jammypkg:deb/ubuntu/sssd?arch=source&distro=noblepkg:deb/ubuntu/sssd?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104033 is a vulnerability in SSSD where, when configured to enforce account expiration via LDAP shadow attributes, an expiration value of zero is not recognized as expired. This allows users with valid credentials on these accounts to bypass access controls and authenticate to the system even after the account should have been deactivated. The flaw affects numerous explicitly listed versions of SSSD, primarily in Ubuntu distributions. The CVSS 3.1 base score is 5.4 (medium severity), reflecting network attack vector, low attack complexity, required privileges, no user interaction, and limited confidentiality and integrity impact.
Potential Impact
Unauthorized access can persist beyond the intended account expiration, allowing users with valid credentials for expired accounts (with expiration value zero) to authenticate and bypass access controls. This undermines account deactivation policies and may lead to unauthorized system access.
Mitigation Recommendations
No explicit patch or remediation status is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is confirmed, administrators should review account expiration configurations and consider additional access controls or monitoring for accounts with expiration value zero.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-104033
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac80fcc2cdf04f65639c4c0
Added to database: 10/08/2026, 21:49:00 UTC
Last enriched: 10/08/2026, 22:18:06 UTC
Last updated: 10/09/2026, 01:48:07 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.