Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18922

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

Отчет

This flaw is rated Critical because it allows a remote, unauthenticated attacker to gain full Directory Manager privileges over an LDAPS connection — with no valid account, no user interaction, and no non-default configuration required. Flaw is exploitable by a remote unauthenticated attacker that fully compromises confidentiality, integrity, and availability without requiring user interaction.

Меры по смягчению последствий

Administrators can restrict nsslapd-allowed-sasl-mechanisms to only the mechanisms actually required (e.g. GSSAPI, EXTERNAL, GSS-SPNEGO), excluding PLAIN. Since the exploit chain requires the first bind attempt to be a failed SASL PLAIN bind as cn=Directory Manager, removing PLAIN from the allowed mechanism list prevents that step entirely — this blocks both the originally reported variant (valid low-privileged account) and the zero-credential SASL ANONYMOUS variant, since both depend on the same initial PLAIN bind to plant the stale identity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 12389-ds-baseAffected
Red Hat Directory Server 13389-ds-baseNot affected
Red Hat Directory Server 11.7 E4S for RHEL 8redhat-dsFixedRHSA-2026:6479208.09.2026
Red Hat Directory Server 11.9 for RHEL 8redhat-dsFixedRHSA-2026:6479308.09.2026
Red Hat Directory Server 12.2 E4S for RHEL 9redhat-dsFixedRHSA-2026:6477908.09.2026
Red Hat Directory Server 12.4 E4S for RHEL 9redhat-dsFixedRHSA-2026:6478008.09.2026
Red Hat Enterprise Linux 10389-ds-baseFixedRHSA-2026:6478508.09.2026
Red Hat Enterprise Linux 10.0 Extended Update Support389-ds-baseFixedRHSA-2026:6480408.09.2026
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION389-ds-baseFixedRHSA-2026:6481108.09.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Support389-ds-baseFixedRHSA-2026:6477108.09.2026

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2511388389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property

EPSS

Процентиль: 45%
0.0056
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
10 дней назад

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

CVSS3: 9.8
nvd
10 дней назад

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

CVSS3: 9.8
debian
10 дней назад

A flaw was found in 389 Directory Server. During SASL PLAIN authentica ...

CVSS3: 9.8
github
10 дней назад

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

rocky
9 дней назад

Critical: 389-ds:1.4 security, bug fix, and enhancement update

EPSS

Процентиль: 45%
0.0056
Низкий

9.8 Critical

CVSS3