CVE-2026-18922
9.8Red Hat · Directory Server
A flaw in 389 Directory Server allows unauthenticated attackers to gain administrative privileges by leveraging stale SASL identity properties during failed bind attempts.
Executive summary
A critical authentication bypass vulnerability in Red Hat Directory Server allows unauthenticated attackers to escalate privileges to Directory Manager status, posing a severe risk to identity infrastructure.
Vulnerability
This vulnerability involves improper authentication within the 389 Directory Server where stale identity information from failed SASL PLAIN bind attempts persists across connections. An unauthenticated attacker can exploit this state to assume the authority of the Directory Manager or other privileged accounts after completing a secondary, unrelated bind.
Business impact
The vulnerability carries a CVSS score of 9.8, reflecting its critical nature and the ease of remote exploitation without authentication. Successful exploitation grants an attacker full control over the directory service, which typically houses sensitive enterprise identity data, credentials, and access control policies. This compromise could lead to widespread unauthorized data access, the creation of backdoors for persistent access, and complete identity provider downtime.
Remediation
Immediate Action: Update your Red Hat Directory Server installations to the versions specified in the Red Hat Security Advisories (RHSA-2026:64771, 64776, 64778, 64779, 64780, 64781, 64783, and 64784) to apply the necessary security patches.
Proactive Monitoring: Review authentication and access logs for suspicious patterns, specifically multiple failed bind attempts followed by successful anonymous or low-privileged bind requests on the same connection.
Compensating Controls: Ensure strict network segmentation for directory services to prevent access from untrusted zones, and implement rigorous monitoring of administrative account activity to detect unauthorized changes or unusual queries.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical severity of this vulnerability and the potential for total directory service compromise, immediate patching is required. IT administrators should prioritize these updates in their next maintenance window to prevent potential exploitation of this authentication flaw.
More Red Hat CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by Red Hat would like to thank Chris Jarrett-Davies (OpenAI Security Research) for reporting this issue., per the CVE Program record.
- RHSA-2026:64771 Vendor advisory
- RHSA-2026:64776 Vendor advisory
- RHSA-2026:64778 Vendor advisory
- RHSA-2026:64779 Vendor advisory
- RHSA-2026:64780 Vendor advisory
- RHSA-2026:64781 Vendor advisory
- RHSA-2026:64783 Vendor advisory
- RHSA-2026:64784 Vendor advisory