Bug 2478616 (CVE-2026-104047) - CVE-2026-104047 sssd: sssd: Information disclosure via query injection in Entra ID lookups
Summary: CVE-2026-104047 sssd: sssd: Information disclosure via query injection in Ent...
Keywords:
Status: NEW
Alias: CVE-2026-104047
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2546638
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-18 03:40 UTC by OSIDB Bzimport
Modified: 2026-10-06 15:45 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-18 03:40:19 UTC
AI_ONLY_REPORT
package: sssd-2.12.0-1.el10
------
Summary: OData Filter Injection in Entra ID Lookup (`oidc_child_id.c`)  
Enables Overbroad Directory Queries: crafted lookup values containing  
single quotes can escape intended OData string literals and broaden Entra  
directory queries issued by the affected lookup path.
Requirements to exploit: A low-privileged local actor must be able to  
trigger name-based lookups on a system that builds and uses the Entra ID  
provider path (`idp_type=entra_id`) with valid directory client credentials  
and scopes. No separate user interaction is required.
Component affected: `sssd-2.12.0-1.el10`, `src/oidc_child/oidc_child_id.c`,  
`entra_id_lookup()`.
Version affected: `sssd-2.12.0-1.el10` when the Entra ID provider path is  
built and deployed with `idp_type=entra_id`.
Patch available: no released package fix established; proposed patch  
included below
Version fixed: unknown
Upstream coordination: Not notified.
CVSS: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - 5.3 (MEDIUM)
AV:L - The issue is reached through a local lookup path rather than  
direct remote network exposure.
AC:L - A crafted lookup value containing a single quote is sufficient to  
alter the generated OData predicate.
PR:L - The attacker needs low privileges sufficient to trigger account  
or group lookups on the affected system.
UI:N - No additional user interaction is required once the lookup is  
issued.
S:U - The impact stays within the same SSSD/IdP lookup security scope.
C:L - Successful exploitation can return broader directory metadata than  
intended, but the exposed data depends on granted directory permissions and  
deployment details.
I:L - The lookup predicate can be changed from the intended exact or  
prefix match to attacker-influenced logic.
A:L - Overbroad responses can increase parsing, processing, and cache  
activity, but the available evidence does not establish reliable  
high-impact exhaustion in all environments.
Impact: Moderate. This issue does not match Red Hat's Important or Critical  
guidance because it is not an unauthenticated remote compromise path and  
depends on a specific Entra ID configuration. In affected deployments,  
however, a low-privileged local actor can change query logic, potentially  
obtain broader directory results than intended, and drive additional  
processing or cache pressure. That supports a configuration-dependent  
compromise of confidentiality, integrity, and availability consistent with  
a Moderate rating.
Embargo: no
Reason: The issue is locally triggered, configuration-dependent, and  
the demonstrated impact is overbroad queries plus extra processing rather  
than remote system compromise. A straightforward code fix exists, so normal  
coordinated disclosure is appropriate.
Acknowledgement: Aisle Research
Vulnerability Details: In `sssd-2.12.0-1.el10`, the Entra ID lookup path  
builds OData `$filter` expressions by inserting user-controlled `input`  
into single-quoted literals without escaping embedded single quotes:
```c
filter = talloc_asprintf(rest_ctx, "startsWith(userPrincipalName,'%s@')",  
input);
filter = talloc_asprintf(rest_ctx, "mail eq '%s' or userPrincipalName  
eq '%s'", input, input);
filter = talloc_asprintf(rest_ctx, "displayName eq '%s'", input);
filter = talloc_asprintf(rest_ctx, "displayName eq '%s' or displayName  
eq '%s'", input, short_name);
```
Only URL encoding is applied afterward:
```c
filter_enc = url_encode_string(rest_ctx, filter);
```
The observed call path shows that the lookup value is forwarded into  
`--name=%s`, `sss_parse_internal_fqname()` does not remove quote  
characters, and returned arrays are later iterated and stored in cache.  
Based on that behavior, a crafted lookup value containing `'` can terminate  
the intended OData string literal and append additional predicate logic  
after the request is decoded by the server. The available evidence supports  
overbroad directory queries and additional backend processing in affected  
Entra ID deployments. It does not establish arbitrary code execution, and  
the maximum disclosure or availability impact will vary with configuration,  
granted directory permissions, and server-side response limits such as  
paging.
Steps to reproduce:
1. Configure the affected package to use the IdP provider with  
`idp_type=entra_id` and valid directory client credentials/scopes.
2. Trigger a name-based lookup with a crafted value containing a single  
quote, for example `a') or startsWith(userPrincipalName,'') or ('1' eq '1`.
3. Enable SSSD debug logging or `--libcurl-debug` and inspect the outgoing  
request to the directory `/users?$filter=` or `/groups?$filter=` endpoint.
4. Confirm that, after URL decoding, the generated `$filter` contains  
injected `or ...` logic instead of a single intended literal comparison or  
prefix test.
5. Compare the response and downstream processing against a benign lookup  
and observe that the injected request can return a broader result set that  
is then iterated and stored by the IdP evaluation path.
Mitigation: Until a package fix is available, avoid enabling the Entra ID  
provider path where it is not required. Where Entra ID integration is  
required, restrict who can trigger name-based lookups with untrusted input  
and monitor for unexpectedly broad directory `$filter` requests. These  
measures reduce exposure but do not eliminate the underlying flaw.
Proposed Fix: Escape single quotes in OData string literals before  
interpolation so that lookup values cannot break out of the intended  
literal. The following minimal patch addresses the affected construction  
sites:
```diff
diff --git a/src/oidc_child/oidc_child_id.c b/src/oidc_child/oidc_child_id.c
— a/src/oidc_child/oidc_child_id.c
+++ b/src/oidc_child/oidc_child_id.c
@@
+static char *odata_escape_single_quotes(TALLOC_CTX *mem_ctx, const char  
*in)
+{
+    size_t i;
+    char *out = NULL;
+
+    if (in == NULL) return NULL;
+    out = talloc_strdup(mem_ctx, "");
+    if (out == NULL) return NULL;
+
+    for (i = 0; in[i] != '\0'; i++) {
+        out = (in[i] == '\'') ? talloc_asprintf_append(out, "''")
+                              : talloc_asprintf_append(out, "%c", in[i]);
+        if (out == NULL) return NULL;
+    }
+    return out;
+}
@@
   char *filter;
+    char *filter;
+    char *input_esc = NULL;
+    char *short_name_esc = NULL;
@@
+    input_esc = odata_escape_single_quotes(rest_ctx, input);
+    if (input_esc == NULL) { ret = ENOMEM; goto done; }
@@

           filter =  
talloc_asprintf(rest_ctx, "startsWith(userPrincipalName,'%s@')", input);
+            filter =  
talloc_asprintf(rest_ctx, "startsWith(userPrincipalName,'%s@')", input_esc);
@@

                                    input, input);
+                                     input_esc, input_esc);
@@

           filter = talloc_asprintf(rest_ctx, "displayName eq '%s'",  
input);
+            filter = talloc_asprintf(rest_ctx, "displayName eq '%s'",  
input_esc);
@@

               filter = talloc_asprintf(rest_ctx, "displayName eq '%s'",  
input);
+                filter = talloc_asprintf(rest_ctx, "displayName eq '%s'",  
input_esc);
              } else {
+                short_name_esc = odata_escape_single_quotes(rest_ctx,  
short_name);
+                if (short_name_esc == NULL) { ret = ENOMEM; goto done; }
                  filter = talloc_asprintf(rest_ctx,
                                           "displayName eq '%s' or  
displayName eq '%s'",

                                        input, short_name);
+                                         input_esc, short_name_esc);
              }
```


------
This report was generated using AI technology. Always review AI-generated  
content prior to use


Note You need to log in before you can comment on or make changes to this bug.