{
  "id": "CVE-2026-104038",
  "url": "https://spydr.io/cve/CVE-2026-104038",
  "published": "2026-10-06T01:16:34.853Z",
  "modified": "2026-10-06T15:09:20.387Z",
  "score": 5.9,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "score_source": "redhat.com",
  "epss": 0.00222,
  "epss_percentile": 0.11753,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": null,
  "vendors": [
    "Red Hat"
  ],
  "products": [
    "Red Hat Enterprise Linux 10",
    "Red Hat Enterprise Linux 6",
    "Red Hat Enterprise Linux 7",
    "Red Hat Enterprise Linux 8",
    "Red Hat Enterprise Linux 9",
    "Red Hat OpenShift Container Platform 4"
  ],
  "cwes": [
    "CWE-476"
  ],
  "description": "A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it, causing the process to crash during authentication or lookup operations.",
  "status": "Awaiting Analysis",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.9,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-104038",
      "tags": []
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2478980",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-104038",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
