VYPR
High severity8.0NVD Advisory· Published Jul 7, 2026· Updated Aug 21, 2026

CVE-2026-14476

CVE-2026-14476

Description

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

33

Patches

Vulnerability mechanics

References

18

News mentions

0

No linked articles in our index yet.