CVE-2026-90462
Last modified
CVE-2026-90462 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results.
Description
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued authorization for a deleted or deprovisioned user. A remote attacker with prior valid account context could exploit this to maintain access to information and potentially make limited modifications to resources that should no longer be available.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | All versions |
| Red Hat | Red Hat Enterprise Linux 6 | All versions |
| Red Hat | Red Hat Enterprise Linux 7 | All versions |
| Red Hat | Red Hat Enterprise Linux 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 9 | All versions |
| Red Hat | Red Hat OpenShift Container Platform 4 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-90462?
How severe is CVE-2026-90462?
How do I fix CVE-2026-90462?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90455A prior update that raised a bundled HTTP client library to …6.3
- CVE-2026-90456An example environment-configuration file for a bundled inve…9.2
- CVE-2026-90457The administrative password is hashed using a comparatively …6.9
- CVE-2026-9046A potential insecure permissions vulnerability was reported …7.3
- CVE-2026-90460An issue was discovered in OpenStack Keystone before 29.0.3.…7.6
- CVE-2026-90461OpenStack Ironic through 38.0.0 may send a username and pass…6.3
- CVE-2026-90463A flaw was found in the sssd NSS responder. This input valid…4
- CVE-2026-90467aiosmtplib before 5.1.3 fails to properly validate email add…4
- CVE-2026-9047Improper handling of factor key state in the multi-factor au…7.6
- CVE-2026-90472msgpack-java through 0.9.12 contains a stack overflow vulner…5.3
- CVE-2026-90473msgpack-java through 0.9.12 contains an integer overflow vul…5.3
- CVE-2026-90474MCPHub before 1.0.32 contains an authentication bypass vulne…6.8
Are you affected by CVE-2026-90462?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
