CVE-2026-14474: Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation

Published Jul 2, 2026
·
Updated

A flaw was found in SSSD's LDAP sudo provider. When the ldapsudosearchbase option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.

Other sources

When ldapsudosearchbase is not explicitly configured (the default), SSSD falls back to the domain's root DN and searches the entire LDAP directory tree for objects matching (objectClass=sudoRole) with SUBTREE scope. Any LDAP principal with write access to any subtree can create a sudoRole object granting arbitrary sudo privileges on every SSSD-enrolled host.

This affects sudoprovider = ldap and sudoprovider = ad (which delegates to sdapsudoinit()). sudoprovider = ipa is NOT affected.

Red Hat

Affected Software

1 affected component
SSSD (sudo LDAP provider)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Set ldap_sudo_search_base explicitly (instead of leaving the default) so SSSD does not search the domain root DN/subtree for (objectClass=sudoRole); limit the search to the DN that contains only the sudoRole objects you intend to grant privileges.

    SSSD (sudo ldap provider / sdap_sudo_init) ldap_sudo_search_base = configured to a specific base DN
  2. Compensating control

    If sudo_provider is set to ldap (or sudo_provider=ad, which delegates to sdap_sudo_init()), restrict LDAP write access so only trusted principals can create/modify sudoRole objects in the LDAP subtree that ldap_sudo_search_base points to.

Event History

Jul 2, 2026
Data Sourced
via Red Hat·02:50 PM
DescriptionSeverityAffected Software
Jul 7, 2026
CVE Published
via MITRE·09:12 AM
Data Sourced
via MITRE·09:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-14474?

CVE-2026-14474 has a severity rating of high, with a score of 8.8.

2

What impact does CVE-2026-14474 have?

CVE-2026-14474 allows an authenticated attacker with write access to a subtree to inject a sudoRole object, potentially granting root-level sudo privileges.

3

How do I fix CVE-2026-14474?

To fix CVE-2026-14474, explicitly configure the ldap_sudo_search_base option in the SSSD configuration to limit the search scope for sudoRole objects.

4

What software is affected by CVE-2026-14474?

CVE-2026-14474 affects the SSSD software specifically when using the sudo LDAP provider.

5

Who is vulnerable to CVE-2026-14474?

Organizations using the SSSD LDAP sudo provider without explicit configuration are vulnerable to CVE-2026-14474.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203