PT-2026-71721 · Opendj · Opendj
CVE-2026-73644
·
Published
2026-07-24
·
Updated
2026-08-18
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenDJ versions prior to 5.1.2
Description
The SASL PLAIN authorization identity path in the
PlainSASLMechanismHandler.java file fails to evaluate the mayProxy proxy ACI (Access Control Instruction) scope when an authorization identity resolves to a different user. Although the PROXIED AUTH privilege is checked, the lack of scope evaluation allows an authenticated account with PROXIED AUTH to assume any resolvable non-root identity, even those not permitted by its proxy ACI. This can be achieved using dn:, u:, or bare authorization identity forms.Recommendations
Update to version 5.1.2.
Exploit
Fix
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opendj