CVE-2026-18922
389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
| CWE | CWE-287 |
| Vendor | red hat |
| Product | red hat directory server 11.7 e4s for rhel 8 |
| Published | Sep 7, 2026 |
| Last Updated | Sep 8, 2026 |
Get instant alerts for red hat red hat directory server 11.7 e4s for rhel 8
Be the first to know when new critical vulnerabilities affecting red hat red hat directory server 11.7 e4s for rhel 8 are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H