Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-18922Critical authentication bypass in 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

View on NVD

Analysis

A critical vulnerability in 389 Directory Server allows an attacker to gain full administrative (Directory Manager) authority without valid credentials. The flaw involves a stale identity being incorrectly applied to a connection after a failed SASL bind followed by an anonymous or low-privileged successful bind.

Relevant roles

ciberseguridadBackendLinuxCloud

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-287

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

Published: 9/7/2026, 3:17:31 PM
Last modified: 9/7/2026, 3:17:31 PM

References

HomeEventsBlogResourcesCoursesTeam