Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE Micro 6.1 Security Advisory 2026-22897-1 SSSD Important Update

suse
Calendar Grey July 27, 2026
Scroller Suse
Install the important SUSE update for sssd to rectify critical security issues including privilege escalation and authentication bypass risks.
SUSE has released an important security update for sssd addressing two vulnerabilities that could allow privilege escalation and Kerberos authentication bypass in SUSE Linux Micro ...

Summary

## This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-626=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libsss_nss_idmap0-2.9.5-slfo.1.1_5.1 * sssd-ldap-debuginfo-2.9.5-slfo.1.1_5.1 * sssd-tools-debuginfo-2.9.5-slfo.1.1_5.1

References

* bsc#1270708

* bsc#1270709

Cross-

* CVE-2026-14474

* CVE-2026-14476

CVSS scores:

* CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

* CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* SUSE Linux Micro 6.1

An update that solves two vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2026-14474.html

* https://www.suse.com/security/cve/CVE-2026-14476.html

* https://bugzilla.suse.com/show_bug.cgi?id=1270708

* https://bugzilla.suse.com/show_bug.cgi?id=1270709

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22897-1
Release Date: 2026-07-22T09:01:06Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.