CVE 6.3 MEDIUM

himmelblau: NSS fake-primary group lookup reintroduces name collision risk_CVE-2026-34397

6.3 / 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated himmelblau users whose mapped CN/short name exactly matches a privileged local group name (e.g., "sudo", "wheel", "docker", "adm") can cause the NSS module to resolve that group name to their fake primary group. If the system uses NSS results for group-based authorization decisions (sudo, polkit, etc.), this can grant the attacker the privileges of that group. This issue has been patched in versions 2.3.9 and 3.1.1.

Basic Information

ID CVE-2026-34397
Source GitHub_M
Published Apr 1, 2026 at 17:25
Modified Apr 4, 2026 at 03:05

Affected Product

Vendor himmelblau-idm
Product himmelblau
Version >= 2.0.0-alpha, < 2.3.9
Affected Versions himmelblau-idm himmelblau >= 2.0.0-alpha, < 2.3.9
himmelblau-idm himmelblau >= 3.0.0-alpha, < 3.1.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.