CVE-2026-18922

9.8

Red Hat · Directory Server

A flaw in 389 Directory Server allows unauthenticated attackers to gain administrative privileges by leveraging stale SASL identity properties during failed bind attempts.

Executive summary

A critical authentication bypass vulnerability in Red Hat Directory Server allows unauthenticated attackers to escalate privileges to Directory Manager status, posing a severe risk to identity infrastructure.

Vulnerability

This vulnerability involves improper authentication within the 389 Directory Server where stale identity information from failed SASL PLAIN bind attempts persists across connections. An unauthenticated attacker can exploit this state to assume the authority of the Directory Manager or other privileged accounts after completing a secondary, unrelated bind.

Business impact

The vulnerability carries a CVSS score of 9.8, reflecting its critical nature and the ease of remote exploitation without authentication. Successful exploitation grants an attacker full control over the directory service, which typically houses sensitive enterprise identity data, credentials, and access control policies. This compromise could lead to widespread unauthorized data access, the creation of backdoors for persistent access, and complete identity provider downtime.

Remediation

Immediate Action: Update your Red Hat Directory Server installations to the versions specified in the Red Hat Security Advisories (RHSA-2026:64771, 64776, 64778, 64779, 64780, 64781, 64783, and 64784) to apply the necessary security patches.

Proactive Monitoring: Review authentication and access logs for suspicious patterns, specifically multiple failed bind attempts followed by successful anonymous or low-privileged bind requests on the same connection.

Compensating Controls: Ensure strict network segmentation for directory services to prevent access from untrusted zones, and implement rigorous monitoring of administrative account activity to detect unauthorized changes or unusual queries.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity of this vulnerability and the potential for total directory service compromise, immediate patching is required. IT administrators should prioritize these updates in their next maintenance window to prevent potential exploitation of this authentication flaw.

More Red Hat CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Red Hat would like to thank Chris Jarrett-Davies (OpenAI Security Research) for reporting this issue., per the CVE Program record.