PT-2026-86818 · Opensuse+2 · 389-Ds+29

CVE-2026-18922

·

Published

2026-09-07

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:64784
CVE-2026-18922
OPENSUSE-SU-2026:11739-1

Affected Products

389-Ds
389-Ds-Base
389-Ds-Base-Devel
389-Ds-Base-Libs
389-Ds-Base-Snmp
Red Hat Directory Server 11
Red Hat Directory Server 11.7 E4S For Rhel 8
Red Hat Directory Server 11.9 For Rhel 8
Red Hat Directory Server 12
Red Hat Directory Server 12.2 E4S For Rhel 9
Red Hat Directory Server 12.4 E4S For Rhel 9
Red Hat Directory Server 13
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 10.0 Extended Update Support
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 6 Extended Lifecycle Support - Extension
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat Enterprise Linux 8.8 Update Services For Sap Solutions
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 9.2 Update Services For Sap Solutions
Red Hat Enterprise Linux 9.4 Update Services For Sap Solutions
Red Hat Enterprise Linux 9.6 Extended Update Support
Python3-Lib389