A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory… (CVE-2026-92821)
Description
A vulnerability in SSSD allows a remote authenticated user with an expired password to bypass access control restrictions when password expiration warnings are evaluated before restrictive LDAP access rules. This flaw occurs because the expired-password warning prematurely terminates rule evaluation and treats the access request as successful. The issue affects multiple specific versions of SSSD and has a CVSS score of 6.8, indicating a medium severity risk.
CVSS v3.1
Score 6.8medium
Affected software
pkg:deb/ubuntu/sssd?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/sssd?arch=source&distro=jammypkg:deb/ubuntu/sssd?arch=source&distro=noblepkg:deb/ubuntu/sssd?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92821 is a vulnerability in SSSD where, if configured to evaluate password expiration warnings before restrictive access rules in LDAP environments, an expired-password warning causes early termination of rule evaluation and incorrectly grants access. A remote authenticated user with an expired password can exploit this by using an alternative authentication method such as SSH public key authentication to bypass access control restrictions and gain unauthorized access to protected systems. The vulnerability affects numerous specific versions of SSSD as listed, and has a CVSS 3.1 score of 6.8 (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
Potential Impact
An attacker who is authenticated but has an expired password can bypass LDAP access control restrictions by exploiting the flaw in SSSD's evaluation order of password expiration warnings and restrictive access rules. This can lead to unauthorized access to protected systems, potentially resulting in confidentiality and integrity impacts. Availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should review SSSD configuration related to password expiration and LDAP access rule evaluation order to mitigate the risk. Avoid configurations that evaluate password expiration warnings before restrictive access rules. Monitor vendor advisories for official patches or updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-92821
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac80fdf2cdf04f65639c84f
Added to database: 10/08/2026, 21:49:19 UTC
Last enriched: 10/08/2026, 22:37:19 UTC
Last updated: 10/09/2026, 04:48:07 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.