CVE-2026-104048:
NixOS 취약성 분석 및 완화
개요
CVE-2026-104048 is an authorization bypass vulnerability in SSSD (System Security Services Daemon) affecting trust-enabled identity management environments. The flaw causes SSSD to evaluate Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames, allowing an authenticated user in a trusted domain to bypass access policies if their username matches an authorized local account. Affected products include SSSD (sssd-2.12.0-1.el10 confirmed), Red Hat Enterprise Linux, and OpenShift RHEL CoreOS 8 and 9 images. The vulnerability was reported on May 18, 2026, and publicly disclosed on October 6, 2026. It carries a CVSS v3.1 base score of 6.8 (Medium/High) (Red Hat CVE, Github Advisory).
기술적 세부 사항
The root cause is classified as CWE-1025 (Comparison Using Wrong Factors): SSSD's IPA HBAC evaluation path calls sss_parse_internal_fqname() to strip the domain qualifier from both the requesting user's identity and the rule's user entry, then performs a case-insensitive comparison of only the resulting shortnames via hbac_evaluate_element() in src/lib/ipa_hbac/hbac_evaluator.c. The affected code paths are in src/providers/ipa/ipa_hbac_common.c (hbac_ctx_to_eval_request(), hbac_eval_user_element()), src/providers/ipa/ipa_hbac_users.c (hbac_user_attrs_to_rule()), and src/lib/ipa_hbac/hbac_evaluator.c. Exploitation requires: (1) a trust-enabled IPA deployment with SSSD HBAC active, (2) an HBAC allow rule that names an IPA-local user directly by username, and (3) an attacker-controlled account in a trusted domain whose shortname matches the local user. The attack vector is network-based (e.g., PAM/SSSD-protected service logins), requires low privileges (valid trusted-domain credentials), and no user interaction (Red Hat Bugzilla, Red Hat CVE).
영향
Successful exploitation allows an authenticated attacker in a trusted domain to bypass HBAC policies and gain unauthorized access to services or hosts that should be restricted to specific local IPA users. Both confidentiality and integrity are rated High, as the bypass can expose sensitive services and permit policy-forbidden actions within the protected service or host context. Availability is not directly impacted. Environments without cross-realm trusts, or those using group-based (rather than user-specific) HBAC rules, are not exposed to this vulnerability (Red Hat CVE, Red Hat Bugzilla).
악용 가능성
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Red Hat CVE). The EPSS score is 0.0, reflecting very low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is constrained by multiple prerequisites: a trust-enabled IPA/SSSD deployment, a shortname collision between domains, and an HBAC rule targeting the local user by name directly. No threat actor attribution has been reported (Github Advisory).
착취 단계
- Reconnaissance: Identify target environments running SSSD with IPA HBAC and cross-domain trust enabled. Enumerate IPA-local usernames that are directly referenced in HBAC allow rules (e.g., via LDAP queries or social engineering).
- Account preparation: In the attacker-controlled trusted domain, create or use an existing account whose shortname (e.g.,
admin) matches the IPA-local user named in the HBAC allow rule. - Authentication attempt: Attempt to authenticate to the HBAC-protected service or host (e.g., SSH, a PAM-protected application) using the trusted-domain account credentials (e.g.,
admin@trusteddomain). - Bypass triggered: SSSD's HBAC evaluation strips the domain qualifier from both the requesting user (
admin@trusteddomain→admin) and the rule entry (admin@localdomain→admin), then performs a case-insensitive match — which succeeds. - Unauthorized access achieved: The attacker gains access to the protected service or host as if they were the authorized local user, enabling further actions within the service's security context (Red Hat Bugzilla).
타협의 징후
- Logs: SSSD debug logs (
/var/log/sssd/) showing HBAC allow decisions for trusted-domain users (e.g.,admin@trusteddomain) matching rules intended for local IPA users; look forhbac_evaluate_elementgranting access where the domain portion differs between the requesting user and the rule subject. - Logs: PAM/authentication logs (
/var/log/secure,/var/log/auth.log) showing successful logins from trusted-domain accounts to services or hosts where those accounts should not have access per policy. - Logs: IPA audit logs showing access grants to services or hosts for users from trusted domains that are not explicitly authorized in HBAC rules by domain-qualified name.
- Network: Unexpected authentication sessions from trusted-domain accounts to HBAC-protected services, particularly where the shortname matches a local privileged account (Red Hat Bugzilla).
완화 및 해결 방법
A formal patched package version had not been released as of the disclosure date; Red Hat states no mitigation meeting their deployment criteria is currently available (Red Hat CVE). The proposed upstream fix preserves the fully qualified internal username for both the request-side and rule-side user elements in HBAC evaluation, preventing domain stripping before comparison (Red Hat Bugzilla). In the interim, administrators should: (1) audit HBAC rules that reference IPA-local users by name and identify shortname collisions with trusted-domain accounts; (2) convert user-specific HBAC rules to group-based rules where possible, as group-based policies are not affected; (3) remove or rename conflicting trusted-domain accounts or restrict trusted-domain logins to non-sensitive services until a fix is available. Monitor the Red Hat Bugzilla entry (Bug 2478613) for patch availability.
커뮤니티 반응
The vulnerability was discovered by AISLE Research in partnership with Red Hat, and Red Hat rates its impact as Moderate due to the deployment-specific prerequisites required for exploitation (Red Hat CVE). Red Hat's advisory notes that environments without cross-realm trusts or those using group-based HBAC policies are not exposed. No significant broader community or media commentary has been identified at this time.
추가 자료
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 NixOS 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."