Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18651

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.

Отчет

This flaw lets a user authenticate to an already-locked account (nsAccountLock: true) via SASL PLAIN, using that account's own correct password. The server checks the password before it checks the lock, so the connection becomes authenticated even though the client is told the bind failed. After bind, the user can read and modify what that account was already permitted to touch - no escalation and access beyond it's own rights.

Меры по смягчению последствий

When locking an account, also rotate its LDAP password. Locking the account alone is not enough: this flaw lets a bind with the account's still-valid password succeed even after it's locked.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11389-ds-baseFix deferred
Red Hat Directory Server 12389-ds-baseFix deferred
Red Hat Directory Server 13389-ds-baseFix deferred
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 6389-ds-baseNot affected
Red Hat Enterprise Linux 7389-ds-baseFix deferred
Red Hat Enterprise Linux 8389-ds:1.4/389-ds-baseFix deferred
Red Hat Enterprise Linux 9389-ds-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2510617389-ds-base: 389-ds-base: SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account

EPSS

Процентиль: 6%
0.00167
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
14 дней назад

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.

CVSS3: 5.4
nvd
14 дней назад

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.

CVSS3: 5.4
debian
14 дней назад

A flaw was found in 389 Directory Server. During SASL PLAIN authentica ...

CVSS3: 5.4
github
13 дней назад

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.

EPSS

Процентиль: 6%
0.00167
Низкий

5.4 Medium

CVSS3