CVE-2026-34397

Source
https://cve.org/CVERecord?id=CVE-2026-34397
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34397.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34397
Aliases
  • GHSA-v7xx-7mqc-g835
Downstream
Related
Published
2026-04-01T17:25:06.034Z
Modified
2026-08-12T03:51:45.545754660Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
himmelblau: NSS fake-primary group lookup reintroduces name collision risk
Details

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated himmelblau users whose mapped CN/short name exactly matches a privileged local group name (e.g., "sudo", "wheel", "docker", "adm") can cause the NSS module to resolve that group name to their fake primary group. If the system uses NSS results for group-based authorization decisions (sudo, polkit, etc.), this can grant the attacker the privileges of that group. This issue has been patched in versions 2.3.9 and 3.1.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34397.json",
    "cwe_ids": [
        "CWE-269"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/himmelblau-idm/himmelblau

Affected ranges

Type
GIT
Repo
https://github.com/himmelblau-idm/himmelblau
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:himmelblau-idm:himmelblau:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.3.9"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.1.1"
        }
    ]
}

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
3.*
3.0.0
3.0.1
3.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34397.json"