AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-14476

HIGH · CVSS 8 EPSS 0.67%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

A path traversal vulnerability in the SSSD's AD GPO provider allows attackers with AD GPO management access to exploit unsanitized ".." sequences in the gPCFileSysPath LDAP attribute, enabling them to write files outside the GPO cache directory as root. This can lead to the injection of malicious Kerberos configurations, potentially resulting in authentication bypass on default RHEL setups with SELinux enforcing. Organizations using affected Linux distributions, particularly those leveraging Active Directory for Group Policy management, should prioritize remediation to mitigate the risk of unauthorized access.

CVE
CVE-2026-14476
Severity
HIGH
CVSS
8
EPSS
0.67%
Linux

Original NVD Description

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.