CVE-2026-18922
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.56%
- CWE
- CWE-287
- Published
- 2026-09-07
- Last modified
- 2026-09-08
Affected products
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support
- Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8
- Red Hat Red Hat Directory Server 12.2 E4S for RHEL 9
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service
- Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
- Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Weakness type
Related vulnerabilities
- CVE-2026-87806 — Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password
- CVE-2026-79974 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-80099 — Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret
- CVE-2026-76009 — Next-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint
- CVE-2026-78560 — Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source
- CVE-2026-86810 — Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication
- CVE-2026-86808 — moltis-org moltis vault.rs vault_recovery_handler missing authentication
- CVE-2026-69854 — Spring Cloud Azure Elevation of Privilege Vulnerability