CVE-2026-34397 Details
Description
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated himmelblau users whose mapped CN/short name exactly matches a privileged local group name (e.g., "sudo", "wheel", "docker", "adm") can cause the NSS module to resolve that group name to their fake primary group. If the system uses NSS results for group-based authorization decisions (sudo, polkit, etc.), this can grant the attacker the privileges of that group. This issue has been patched in versions 2.3.9 and 3.1.1.
A conditional local privilege escalation vulnerability has been identified in Himmelblau, an interoperability suite for Microsoft Azure Entra ID and Intune. This vulnerability affects Himmelblau versions 2.0.0-alpha prior to 2.3.9 and 3.0.0-alpha prior to 3.1.1. The issue arises from an edge-case naming collision where authenticated users can manipulate group name resolutions to gain unauthorized privileges. Specifically, if a user's mapped short name matches that of a privileged local group (such as 'sudo', 'wheel', 'docker', or 'adm'), the NSS module can be tricked into assigning that group’s privileges to the user. This exploitation is possible in environments where Himmelblau is integrated with NSS for group lookups and the 'cn_name_mapping' feature is enabled, which is the default setting.
Users can upgrade to Himmelblau versions 2.3.9 or 3.1.1, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/himmelblau-idm/himmelblau/releases/tag/2.3.9 | [email protected] | ProductRelease Notes |
| https://github.com/himmelblau-idm/himmelblau/releases/tag/3.1.1 | [email protected] | ProductRelease Notes |
| https://github.com/himmelblau-idm/himmelblau/security/advisories/GHSA-v7xx-7mqc-g835 | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| himmelblau-idm himmelblau | >= 2.0.0, < 2.3.9 >= 3.0.0, < 3.1.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | Reanalysis | [email protected] |
| Apr 15, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |