Hi, The following vulnerability was published for sssd. CVE-2026-87853[0]: | A flaw was found in SSSD's IdP authentication provider. The | eval_access_token_buf() function compares the OIDC subject | identifier using strncmp() with the authenticated user's identifier | length, performing a prefix comparison instead of an exact match. An | attacker whose IdP identifier is a strict prefix of a target user's | identifier can authenticate as the target user. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-87853 https://www.cve.org/CVERecord?id=CVE-2026-87853 [1] https://github.com/SSSD/sssd/pull/9250 [2] https://github.com/SSSD/sssd/commit/f3a324918c1a35bd0195a1de5b17897a0d3b6274 (master) https://github.com/SSSD/sssd/commit/8180e70a2708dbf8ac6f089119922dec81fcc503 (sssd-2-13) https://github.com/SSSD/sssd/commit/542411bb0b6e4171d9183fbf364d6cb52d848ad5 (sssd-2-12) Please adjust the affected versions in the BTS as needed. Regards, Salvatore