CVE-2025-11561
A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.80%
- CWE
- CWE-269
- Published
- 2025-10-09
- Last modified
- 2026-08-31
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Weakness type
Related vulnerabilities
- CVE-2026-84869 — ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
- CVE-2026-79090 — Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soci
- CVE-2026-79226 — Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
- CVE-2026-78999 — Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co
- CVE-2026-73269 — Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa
- CVE-2026-9193 — Privilege escalation in Progress MarkLogic Server Hadoop integration
- CVE-2026-8709 — Privilege escalation in Progress MarkLogic Server REST document patch operation
- CVE-2026-7329 — Privilege escalation in Progress MarkLogic Server REST query interfaces