An unauthenticated LDAP client can become Directory Manager on 389 Directory Server.
One failed privileged bind followed by an anonymous bind installs the stale privileged identity.
389 Directory Server, the Linux LDAP identity server used directly and by Red Hat directory products.
Unauthenticated Directory Manager authority
The two-bind sequence yields the directory's highest authority and compromises the trust root used by relying services.
Detail and 2 sources
The attacker first submits an incorrect password in a SASL PLAIN bind as Directory Manager, leaving the privileged DN in a Cyrus SASL auxiliary property.
A SASL ANONYMOUS bind on the same connection then installs that stale identity.
Pre-fix images remain accepted, and revocation is incomplete despite publication of a fixed upstream version.
- access:network:lan
- reachable from the local network
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Revocation complete
- No
- Reaches end-of-life hardware
- Yes
The tracker lists additional relevant errata beyond the four supplied, including RHSA-2026:64771 for RHEL 7 ELS and RHSA-2026:64811 for RHEL 6 ELS Extension.