Red Hat released Important security updates for sssd to address two vulnerabilities tracked as CVE-2026-14474 and CVE-2026-14476 across multiple Red Hat Enterprise Linux versions and support channels, including RHEL 7 ELS, RHEL 8.4/8.6/8.8, RHEL 9.2/9.4/9.6, and RHEL 10, as well as related SAP, AUS, EUS, ELS, and CodeReady Linux Builder offerings. The first flaw affects deployments using sudo_provider=ldap or sudo_provider=ad: when ldap_sudo_search_base is left unset, SSSD searches from the LDAP domain root for sudoRole objects, allowing an LDAP principal with write access in any subtree to create a malicious rule that grants arbitrary sudo privileges on every enrolled host. Red Hat said sudo_provider=ipa is not affected.
The second flaw, CVE-2026-14476, stems from unsanitized gPCFileSysPath handling in SSSD's Active Directory GPO provider, enabling path traversal through .. components after backslashes are converted to forward slashes. Red Hat warned that an attacker with AD GPO management access could write files outside the GPO cache as root; on SELinux-enforcing systems this can be used to target /var/lib/sss/pubconf/krb5.include.d/ and redirect Kerberos KDC configuration for authentication bypass, while systems with SELinux permissive or disabled may face arbitrary root file write. Fixes were shipped through RHSA advisories including RHSA-2026:41937, RHSA-2026:42122, RHSA-2026:46482, and a series of August updates covering older and specialized RHEL channels.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-04, Red Hat published RHSA-2026:50109 for Red Hat Enterprise Linux 7 Extended Lifecycle Support, fixing CVE-2026-14474 and CVE-2026-14476 with updated sssd packages version 1.16.5-10.el7_9.18.
On 2026-08-04, Red Hat published RHSA-2026:49839 for Red Hat Enterprise Linux 9.6 Extended Update Support and related offerings, fixing CVE-2026-14474 and CVE-2026-14476.
On 2026-08-04, Red Hat published RHSA-2026:49840 for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related 9.4 channels, fixing CVE-2026-14474 and CVE-2026-14476 with sssd 2.9.4-6.el9_4.5.
On 2026-08-04, Red Hat published RHSA-2026:49843 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 channels, fixing CVE-2026-14474 and CVE-2026-14476 with sssd 2.8.2-5.el9_2.7.
On 2026-08-04, Red Hat published RHSA-2026:49842 for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and 8.8 Telecommunications Update Service, fixing CVE-2026-14474 and CVE-2026-14476 with sssd 2.8.2-4.el8_8.4.
On 2026-08-04, Red Hat published RHSA-2026:49844 for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On, fixing CVE-2026-14474 and CVE-2026-14476 with sssd 2.6.2-4.el8_6.5.
On 2026-08-04, Red Hat published RHSA-2026:49841 for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On, fixing CVE-2026-14474 and CVE-2026-14476 with sssd 2.4.0-9.el8_4.5.
On 2026-07-27, Red Hat published RHSA-2026:46482 for Red Hat Enterprise Linux 10.0 Extended Update Support, fixing CVE-2026-14474 and CVE-2026-14476 with updated sssd packages version 2.10.2-3.el10_0.5.
On 2026-07-20, Red Hat's Bugzilla documented CVE-2026-14476 as an SSSD AD GPO path traversal flaw in ad_gpo_extract_smb_components() that can enable Kerberos authentication bypass or arbitrary root file write depending on SELinux configuration.
On 2026-07-20, Red Hat's Bugzilla documented CVE-2026-14474 as an SSSD flaw where the sudo LDAP provider searches the LDAP domain root subtree by default, enabling privilege escalation if an attacker can create sudoRole objects in writable subtrees.
On 2026-07-20, Red Hat published RHSA-2026:41937 for Red Hat Enterprise Linux 10, addressing CVE-2026-14474 and CVE-2026-14476 in sssd with an Important severity rating.
On 2026-07-20, Red Hat published RHSA-2026:42122 for Red Hat Enterprise Linux 9, fixing CVE-2026-14474 and CVE-2026-14476 in sssd and rating the update Important.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.