CVE-2026-18922
CRITICALCVSS 9.8A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
CVSS v3: 9.8 (CRITICAL)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- https://access.redhat.com/errata/RHSA-2026:64771
- https://access.redhat.com/errata/RHSA-2026:64776
- https://access.redhat.com/errata/RHSA-2026:64778
- https://access.redhat.com/errata/RHSA-2026:64779
- https://access.redhat.com/errata/RHSA-2026:64781
- https://access.redhat.com/errata/RHSA-2026:64783
- https://access.redhat.com/errata/RHSA-2026:64789
- https://access.redhat.com/errata/RHSA-2026:64792
- https://access.redhat.com/errata/RHSA-2026:64804
- https://access.redhat.com/security/cve/CVE-2026-18922
- https://bugzilla.redhat.com/show_bug.cgi?id=2511388
Source: NIST NVD · Data may lag official sources by up to one minute