Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.6%top 55%

CVE-2026-14474: Initialization of a Resource with an Insecure Default in Red Hat Red Hat Enterprise Linux 10

0
High
Published: 07/07/2026 (07/07/2026, 09:12:33 UTC)
Source: GCVE Database
Vendor/Project: Red Hat
Product: Red Hat Enterprise Linux 10

Description

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

redhat/sssd
pkg:rpm/redhat/sssd
Affected versions
=10<10.2.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 18:41:16 UTC

Technical Analysis

The System Security Services Daemon (SSSD) in Red Hat Enterprise Linux versions 9 and 10 contained two important security flaws. CVE-2026-14474 is a privilege escalation vulnerability caused by the sudo LDAP provider searching the entire directory tree for sudoRole objects by default, potentially granting unauthorized elevated privileges. CVE-2026-14476 is a Kerberos authentication bypass vulnerability caused by a path traversal in the GPO cache due to an unsanitized gPCFileSysPath. These vulnerabilities affect multiple architectures and variants of Red Hat Enterprise Linux 9 and 10, including AppStream, BaseOS, and CRB. Red Hat has issued official security advisories and released patched packages to remediate these issues.

Potential Impact

Successful exploitation of CVE-2026-14474 could allow an attacker to escalate privileges by leveraging the sudo LDAP provider's default behavior of searching the entire directory tree for sudoRole objects. CVE-2026-14476 could allow an attacker to bypass Kerberos authentication by exploiting a path traversal vulnerability in the GPO cache. Both vulnerabilities compromise authentication and authorization mechanisms, potentially allowing unauthorized access or elevated privileges on affected systems.

Mitigation Recommendations

Red Hat has released official security updates that address these vulnerabilities. Users should apply the provided patches for Red Hat Enterprise Linux 9 and 10 as described in the Red Hat advisories RHSA-2026:41937 and RHSA-2026:42122. Detailed instructions for applying these updates are available at https://access.redhat.com/articles/11258. Since patches are available, applying these updates is the recommended and effective mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:41937
Cve Count
2
Additional Cves
["CVE-2026-14476"]
Cvss Version
null

Threat ID: 6a5e7a022a4a8d59899d8876

Added to database: 07/20/2026, 19:41:54 UTC

Last enriched: 08/12/2026, 18:41:16 UTC

Last updated: 09/03/2026, 22:52:09 UTC

Views: 95

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:41937https://access.redhat.com/security/updates/classification/#important24965562496581Canonical URLhttps://access.redhat.com/errata/RHSA-2026:42122Canonical URLhttps://access.redhat.com/errata/RHSA-2026:46990RHEL-168415Canonical URLhttps://access.redhat.com/errata/RHSA-2026:46482Canonical URLhttps://access.redhat.com/errata/RHSA-2026:49839Canonical URLhttps://access.redhat.com/errata/RHSA-2026:49840Canonical URLhttps://access.redhat.com/errata/RHSA-2026:49841Canonical URLReference 19Reference 20Reference 21Reference 22Reference 23Reference 24Reference 25Reference 26Reference 27Reference 28Canonical URLCanonical URLReference 31Reference 32Canonical URLCanonical URLWID-SEC-W-2026-2419 - CSAF VersionWID-SEC-2026-2419 - Portal VersionRed Hat Security Advisory RHSA-2026:42089 vom 2026-07-20Red Hat Security Advisory RHSA-2026:42090 vom 2026-07-20Red Hat Security Advisory RHSA-2026:42096 vom 2026-07-20SUSE Security Update SUSE-SU-2026:3139-1 vom 2026-07-21Oracle Linux Security Advisory ELSA-2026-41937 vom 2026-07-21Oracle Linux Security Advisory ELSA-2026-42089 vom 2026-07-21Oracle Linux Security Advisory ELSA-2026-42063 vom 2026-07-21Amazon Linux Security Advisory ALAS2-2026-3803 vom 2026-07-21Oracle Linux Security Advisory ELSA-2026-42090 vom 2026-07-21Rocky Linux Security Advisory RLSA-2026:42122 vom 2026-07-22Rocky Linux Security Advisory RLSA-2026:42096 vom 2026-07-22Rocky Linux Security Advisory RLSA-2026:42089 vom 2026-07-22Rocky Linux Security Advisory RLSA-2026:42063 vom 2026-07-22Rocky Linux Security Advisory RLSA-2026:41937 vom 2026-07-22SUSE Security Update SUSE-SU-2026:3195-1 vom 2026-07-22Oracle Linux Security Advisory ELSA-2026-42122 vom 2026-07-23Reference 53Reference 54Reference 55Reference 56Reference 57Reference 58Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses