PT-2026-66736 · Unknown+1 · 389 Directory Server+1

·

CVE-2026-11770

·

Published

2026-07-31

·

Updated

2026-09-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions 389 Directory Server (affected versions not specified)
Description An unauthenticated remote attacker can perform an LDAP filter injection within the CleanAllRUV replication status-check extended operation. The handler executes the search against cn=config using elevated replication plugin privileges and returns a boolean match result. This allows an attacker to extract sensitive server configuration metadata, such as replication bind DNs and password storage scheme information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55423
ALSA-2026:55424
ALSA-2026:55530
AZL-94365
CVE-2026-11770
OPENSUSE-SU-2026:11739-1
RHSA-2026:55421
RHSA-2026:55422
RHSA-2026:55423
RHSA-2026:55424
RHSA-2026:55425
RHSA-2026:55426
RHSA-2026:55530
RHSA-2026:55532
RHSA-2026:55756
RHSA-2026:55757
RHSA-2026:55758
RHSA-2026:55794
RHSA-2026:56047
RHSA-2026:56048
RHSA-2026:56050

Affected Products

389 Directory Server
Rocky Linux