Количество 11
Количество 11
GHSA-pr87-24g5-hphv
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
CVE-2026-18922
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
CVE-2026-18922
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
CVE-2026-18922
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
CVE-2026-18922
A flaw was found in 389 Directory Server. During SASL PLAIN authentica ...
RLSA-2026:64791
Critical: 389-ds:1.4 security, bug fix, and enhancement update
ELSA-2026-64791-0
ELSA-2026-64791-0: 389-ds:1.4 security, bug fix, and enhancement update (CRITICAL)
RLSA-2026:64785
Critical: 389-ds-base security, bug fix, and enhancement update
RLSA-2026:64784
Critical: 389-ds-base security, bug fix, and enhancement update
ELSA-2026-64785-0
ELSA-2026-64785-0: 389-ds-base security, bug fix, and enhancement update (CRITICAL)
ELSA-2026-64784-0
ELSA-2026-64784-0: 389-ds-base security, bug fix, and enhancement update (CRITICAL)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-pr87-24g5-hphv A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible. | CVSS3: 9.8 | 1% Низкий | 10 дней назад | |
CVE-2026-18922 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible. | CVSS3: 9.8 | 1% Низкий | 10 дней назад | |
CVE-2026-18922 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible. | CVSS3: 9.8 | 1% Низкий | 10 дней назад | |
CVE-2026-18922 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible. | CVSS3: 9.8 | 1% Низкий | 10 дней назад | |
CVE-2026-18922 A flaw was found in 389 Directory Server. During SASL PLAIN authentica ... | CVSS3: 9.8 | 1% Низкий | 10 дней назад | |
RLSA-2026:64791 Critical: 389-ds:1.4 security, bug fix, and enhancement update | 9 дней назад | |||
ELSA-2026-64791-0 ELSA-2026-64791-0: 389-ds:1.4 security, bug fix, and enhancement update (CRITICAL) | 8 дней назад | |||
RLSA-2026:64785 Critical: 389-ds-base security, bug fix, and enhancement update | 8 дней назад | |||
RLSA-2026:64784 Critical: 389-ds-base security, bug fix, and enhancement update | 8 дней назад | |||
ELSA-2026-64785-0 ELSA-2026-64785-0: 389-ds-base security, bug fix, and enhancement update (CRITICAL) | 10 дней назад | |||
ELSA-2026-64784-0 ELSA-2026-64784-0: 389-ds-base security, bug fix, and enhancement update (CRITICAL) | 10 дней назад |
Уязвимостей на страницу