Skip to finding
§
High
Research
Confirmed
CVE-2026-18922

An unauthenticated LDAP client can become Directory Manager on 389 Directory Server.

One failed privileged bind followed by an anonymous bind installs the stale privileged identity.

Affects

389 Directory Server, the Linux LDAP identity server used directly and by Red Hat directory products.

What it enables

Unauthenticated Directory Manager authority

Connect to the LDAP service without credentials.→↓Attempt a SASL PLAIN bind as cn=Directory Manager with an incorrect password; the bind fails but leaves the privileged DN in a Cyrus SASL auxiliary property.→↓Complete a SASL ANONYMOUS bind on the same connection.→↓The server installs the stale Directory Manager identity and grants full directory authority.
Why this matters

The two-bind sequence yields the directory's highest authority and compromises the trust root used by relying services.

Detail and 2 sources
Required access

Network reachability to an affected 389 Directory Server over LDAP or LDAPS

Affected versions

389-ds-base 2.9.0 confirmed; the vulnerable logic was unchanged from commit 33c0e0115c03017ba94ee02f144383704de32a25, Affected Red Hat Enterprise Linux 6, 7, 8, 9 and 10 and Red Hat Directory Server 11 and 12 streams identified by Red Hat errata

Proof of concept

Demonstrated by the researcher

The attacker first submits an incorrect password in a SASL PLAIN bind as Directory Manager, leaving the privileged DN in a Cyrus SASL auxiliary property.

A SASL ANONYMOUS bind on the same connection then installs that stale identity.

Pre-fix images remain accepted, and revocation is incomplete despite publication of a fixed upstream version.

Evidence
Red Hat CNA documents the zero-credential bind sequence and resulting Directory Manager identityRed Hat Product Security independently reproduced the result against 389-ds-base 2.9.0Exact fixed upstream version is public
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 8, 2026