DEBIAN-CVE-2026-87853
Dashboard / Vulnerabilities / DEBIAN-CVE-2026-87853
Summary:
Details: A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.
Affected packages
Package
Name: sssd
Purl: pkg:deb/debian/sssd?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
2.10.1-1
2.10.1-2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
