A flaw was found in SSSD's IdP authentication provider. (CVE-2026-87853)
Description
A vulnerability in SSSD's IdP authentication provider allows an attacker to authenticate as another user if the attacker's IdP identifier is a strict prefix of the target user's identifier. This is due to a prefix comparison flaw in the eval_access_token_buf() function that uses strncmp() incorrectly. The issue affects multiple specific versions of SSSD. The CVSS score is 7.5, indicating a medium severity level.
CVSS v3.1
Score 7.5high
Affected software
pkg:deb/ubuntu/sssd?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/sssd?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/sssd?arch=source&distro=jammypkg:deb/ubuntu/sssd?arch=source&distro=noblepkg:deb/ubuntu/sssd?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-87853 is a vulnerability in the System Security Services Daemon (SSSD) IdP authentication provider. The flaw arises because the eval_access_token_buf() function compares the OpenID Connect (OIDC) subject identifier using strncmp() with the length of the authenticated user's identifier, resulting in a prefix comparison rather than an exact match. Consequently, an attacker whose IdP identifier is a strict prefix of a legitimate user's identifier can bypass authentication and impersonate that user. This affects numerous specific versions of SSSD as listed. The vulnerability has a CVSS 3.1 base score of 7.5, with network attack vector, high impact on confidentiality, integrity, and availability, and requires low privileges and high attack complexity.
Potential Impact
An attacker can authenticate as another user if their IdP identifier is a strict prefix of the target user's identifier. This leads to unauthorized access with the privileges of the impersonated user, impacting confidentiality, integrity, and availability of the system. The vulnerability requires network access and low privileges but has a high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should monitor for updates from the SSSD maintainers or their Linux distribution vendors. No vendor advisory or patch links are provided in the current data, so no specific remediation steps can be recommended beyond awaiting an official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-87853
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac80fe22cdf04f65639c870
Added to database: 10/08/2026, 21:49:22 UTC
Last enriched: 10/08/2026, 22:38:52 UTC
Last updated: 10/08/2026, 23:34:03 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.