Описание
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-18922
- https://bugzilla.redhat.com/show_bug.cgi?id=2511388
- https://access.redhat.com/security/cve/CVE-2026-18922
- https://access.redhat.com/errata/RHSA-2026:64811
- https://access.redhat.com/errata/RHSA-2026:64804
- https://access.redhat.com/errata/RHSA-2026:64793
- https://access.redhat.com/errata/RHSA-2026:64792
- https://access.redhat.com/errata/RHSA-2026:64791
- https://access.redhat.com/errata/RHSA-2026:64790
- https://access.redhat.com/errata/RHSA-2026:64789
- https://access.redhat.com/errata/RHSA-2026:64785
- https://access.redhat.com/errata/RHSA-2026:64784
- https://access.redhat.com/errata/RHSA-2026:64783
- https://access.redhat.com/errata/RHSA-2026:64781
- https://access.redhat.com/errata/RHSA-2026:64780
- https://access.redhat.com/errata/RHSA-2026:64779
- https://access.redhat.com/errata/RHSA-2026:64778
- https://access.redhat.com/errata/RHSA-2026:64776
- https://access.redhat.com/errata/RHSA-2026:64771
Связанные уязвимости
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
A flaw was found in 389 Directory Server. During SASL PLAIN authentica ...