CVE-2026-104047: Sssd: sssd: information disclosure via query injection in entra id lookups

Published May 18, 2026
·
Updated

A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory.

Other sources

AIONLYREPORT package: sssd-2.12.0-1.el10 ------ Summary: OData Filter Injection in Entra ID Lookup (oidcchildid.c) Enables Overbroad Directory Queries: crafted lookup values containing single quotes can escape intended OData string literals and broaden Entra directory queries issued by the affected lookup path. Requirements to exploit: A low-privileged local actor must be able to trigger name-based lookups on a system that builds and uses the Entra ID provider path (idptype=entraid) with valid directory client credentials and scopes. No separate user interaction is required. Component affected: sssd-2.12.0-1.el10, src/oidcchild/oidcchildid.c, entraidlookup(). Version affected: sssd-2.12.0-1.el10 when the Entra ID provider path is built and deployed with idptype=entraid. Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - 5.3 (MEDIUM) AV:L - The issue is reached through a local lookup path rather than direct remote network exposure. AC:L - A crafted lookup value containing a single quote is sufficient to alter the generated OData predicate. PR:L - The attacker needs low privileges sufficient to trigger account or group lookups on the affected system. UI:N - No additional user interaction is required once the lookup is issued. S:U - The impact stays within the same SSSD/IdP lookup security scope. C:L - Successful exploitation can return broader directory metadata than intended, but the exposed data depends on granted directory permissions and deployment details. I:L - The lookup predicate can be changed from the intended exact or prefix match to attacker-influenced logic. A:L - Overbroad responses can increase parsing, processing, and cache activity, but the available evidence does not establish reliable high-impact exhaustion in all environments. Impact: Moderate. This issue does not match Red Hat's Important or Critical guidance because it is not an unauthenticated remote compromise path and depends on a specific Entra ID configuration. In affected deployments, however, a low-privileged local actor can change query logic, potentially obtain broader directory results than intended, and drive additional processing or cache pressure. That supports a configuration-dependent compromise of confidentiality, integrity, and availability consistent with a Moderate rating. Embargo: no Reason: The issue is locally triggered, configuration-dependent, and the demonstrated impact is overbroad queries plus extra processing rather than remote system compromise. A straightforward code fix exists, so normal coordinated disclosure is appropriate. Acknowledgement: Aisle Research Vulnerability Details: In sssd-2.12.0-1.el10, the Entra ID lookup path builds OData $filter expressions by inserting user-controlled input into single-quoted literals without escaping embedded single quotes: c filter = tallocasprintf(restctx, "startsWith(userPrincipalName,'%s@')", input); filter = tallocasprintf(restctx, "mail eq '%s' or userPrincipalName eq '%s'", input, input); filter = tallocasprintf(restctx, "displayName eq '%s'", input); filter = tallocasprintf(restctx, "displayName eq '%s' or displayName eq '%s'", input, shortname); Only URL encoding is applied afterward: c filterenc = urlencodestring(restctx, filter); The observed call path shows that the lookup value is forwarded into --name=%s, sssparseinternalfqname() does not remove quote characters, and returned arrays are later iterated and stored in cache. Based on that behavior, a crafted lookup value containing ' can terminate the intended OData string literal and append additional predicate logic after the request is decoded by the server. The available evidence supports overbroad directory queries and additional backend processing in affected Entra ID deployments. It does not establish arbitrary code execution, and the maximum disclosure or availability impact will vary with configuration, granted directory permissions, and server-side response limits such as paging. Steps to reproduce: 1. Configure the affected package to use the IdP provider with idptype=entraid and valid directory client credentials/scopes. 2. Trigger a name-based lookup with a crafted value containing a single quote, for example a') or startsWith(userPrincipalName,'') or ('1' eq '1. 3. Enable SSSD debug logging or --libcurl-debug and inspect the outgoing request to the directory /users?$filter= or /groups?$filter= endpoint. 4. Confirm that, after URL decoding, the generated $filter contains injected or ... logic instead of a single intended literal comparison or prefix test. 5. Compare the response and downstream processing against a benign lookup and observe that the injected request can return a broader result set that is then iterated and stored by the IdP evaluation path. Mitigation: Until a package fix is available, avoid enabling the Entra ID provider path where it is not required. Where Entra ID integration is required, restrict who can trigger name-based lookups with untrusted input and monitor for unexpectedly broad directory $filter requests. These measures reduce exposure but do not eliminate the underlying flaw. Proposed Fix: Escape single quotes in OData string literals before interpolation so that lookup values cannot break out of the intended literal. The following minimal patch addresses the affected construction sites: diff diff --git a/src/oidcchild/oidcchildid.c b/src/oidcchild/oidcchildid.c — a/src/oidcchild/oidcchildid.c +++ b/src/oidcchild/oidcchildid.c @@ +static char odataescapesinglequotes(TALLOCCTX memctx, const char in) +{ + sizet i; + char out = NULL; + + if (in == NULL) return NULL; + out = tallocstrdup(memctx, ""); + if (out == NULL) return NULL; + + for (i = 0; in[i] != '\0'; i++) { + out = (in[i] == '\'') ? tallocasprintfappend(out, "''") + : tallocasprintfappend(out, "%c", in[i]); + if (out == NULL) return NULL; + } + return out; +} @@ char filter; + char filter; + char inputesc = NULL; + char shortnameesc = NULL; @@ + inputesc = odataescapesinglequotes(restctx, input); + if (inputesc == NULL) { ret = ENOMEM; goto done; } @@

filter = tallocasprintf(restctx, "startsWith(userPrincipalName,'%s@')", input); + filter = tallocasprintf(restctx, "startsWith(userPrincipalName,'%s@')", inputesc); @@

input, input); + inputesc, inputesc); @@

filter = tallocasprintf(restctx, "displayName eq '%s'", input); + filter = tallocasprintf(restctx, "displayName eq '%s'", inputesc); @@

filter = tallocasprintf(restctx, "displayName eq '%s'", input); + filter = tallocasprintf(restctx, "displayName eq '%s'", inputesc); } else { + shortnameesc = odataescapesinglequotes(restctx, shortname); + if (shortnameesc == NULL) { ret = ENOMEM; goto done; } filter = tallocasprintf(restctx, "displayName eq '%s' or displayName eq '%s'",

input, shortname); + inputesc, shortnameesc); }

------ This report was generated using AI technology. Always review AI-generated content prior to use

— Red Hat

Affected Software

7 affected components
redhat/sssd=2.12.0-1.el10
Fedoraproject Sssd=2.12.0
redhat OpenShift Container Platform=4.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Avoid enabling the Entra ID provider path where it is not required.

    SSSD Entra ID provider idp_type = not enabled
  2. Compensating control

    Escape single quotes in OData string literals before interpolating lookup values: replace each embedded single quote with two single quotes (''), so values cannot terminate the intended literal or append predicate logic.

  3. Compensating control

    Restrict who can trigger name-based lookups with untrusted input on affected systems.

  4. Compensating control

    Enable SSSD debug logging or --libcurl-debug and monitor outgoing /users?$filter= and /groups?$filter= requests for unexpectedly broad directory filters.

Event History

May 18, 2026
Data Sourced
via Red Hat·03:40 AM
DescriptionSeverityAffected Software
Oct 6, 2026
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203