A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.
Conclusion & alert: CVE-2025-11561 is rated Moderate Risk (53.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.77%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.77% | +0.72% |
| 2 | 2026-06-14 | 0.05% | 0.05% | +0.01% |
| 3 | 2026-05-15 | — | 0.05% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-11561 not yet assigned priority: Debian including 1 source packages (sssd), 4 status rows across 4 suites (bookworm, bullseye, sid, trixie): open 3, resolved 1. | https://security-tracker.debian.org/tracker/CVE-2025-11561 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-11561 |
suse
|
high | CVE-2025-11561 severity important: SUSE including 387 source package names (13.2-9.1:libgcc_s1-13.3.0+git8781-2.1, 13.2-9.1:libstdc++6-13.3.0+git8781-2.1, …), 1018 product×package rows across 95 product lines (Container suse/manager/5.0/x86_64/server, Container suse/multi-linux-manager/5.1/x86_64/server, … (95 product lines)): Fixed 994, First Fixed 24. | https://www.suse.com/security/cve/CVE-2025-11561/ |
ubuntu
|
medium | CVE-2025-11561 medium priority: Ubuntu including 1 source packages (sssd), 8 status rows across 8 suites (bionic, focal, jammy, noble, plucky, questing, upstream, xenial): ignored 7, needs-triage 1. | https://ubuntu.com/security/CVE-2025-11561 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||