Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76560

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.

Отчет

This flaw affects any 389 Directory Server (or Red Hat Directory Server) deployment that defines an ACI using a userattr="attribute#SELFDN" or userattr="attribute#USERDN" bind rule on an attribute that is permitted to hold an explicit empty value. Red Hat Directory Server does not ship such an ACI by default; real-world impact depends on whether a specific deployment or consuming application defines an ACI of this shape.

Меры по смягчению последствий

Until a fix is available, review all ACIs using userattr="...#SELFDN" bind rules and confirm the target attribute cannot be set to an empty value, or add an explicit authmethod restriction to the ACI to prevent anonymous binds from satisfying the check. Where anonymous binds are not required, disabling anonymous access to the directory removes the attack surface entirely.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11389-ds-baseAffected
Red Hat Directory Server 12389-ds-baseAffected
Red Hat Directory Server 12redhat-ds:12/389-ds-baseAffected
Red Hat Directory Server 13389-ds-baseNot affected
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 8389-ds-baseAffected
Red Hat Directory Server 11.7 E4S for RHEL 8redhat-dsFixedRHSA-2026:6479208.09.2026
Red Hat Directory Server 11.9 for RHEL 8redhat-dsFixedRHSA-2026:6479308.09.2026
Red Hat Directory Server 12.2 E4S for RHEL 9redhat-dsFixedRHSA-2026:6477908.09.2026
Red Hat Directory Server 12.4 E4S for RHEL 9redhat-dsFixedRHSA-2026:6478008.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2519521389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN

EPSS

Процентиль: 30%
0.00367
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 дней назад

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.

CVSS3: 7.5
nvd
10 дней назад

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.

CVSS3: 7.5
debian
10 дней назад

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule eva ...

CVSS3: 7.5
github
10 дней назад

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.

rocky
9 дней назад

Critical: 389-ds:1.4 security, bug fix, and enhancement update

EPSS

Процентиль: 30%
0.00367
Низкий

7.5 High

CVSS3