CVE-2026-104048
CVE-2026-104048 is a medium-severity vulnerability with a CVSS 3.x base score of 6.8. The underlying weakness is classified as CWE-1025.
Key facts
- Severity: Medium (CVSS 3.x base score 6.8)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1025
- Published:
- Last modified:
Description
A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts.
Frequently asked questions
- What is CVE-2026-104048?
- A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts.
- How severe is CVE-2026-104048?
- CVE-2026-104048 has a CVSS 3.x base score of 6.8, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-104048 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-104048?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-104048 published?
- CVE-2026-104048 was published on 2026-10-06.
References
- https://access.redhat.com/security/cve/CVE-2026-104048
- https://bugzilla.redhat.com/show_bug.cgi?id=2478613
Other CWE-1025 vulnerabilities
- CVE-2025-71377 — High (CVSS 8.7): stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching…
- CVE-2026-100248 — High (CVSS 8.4): The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
- CVE-2026-9800 — High (CVSS 8.1): A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all…
- CVE-2026-40880 — High (CVSS 8.1): ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a…
- CVE-2026-29811 — High (CVSS 7.7): CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a…
- CVE-2023-54390 — High (CVSS 7.5): PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing…