CVE-2026-76560
7.5Red Hat · Directory Server
A flaw in 389 Directory Server allows unauthenticated LDAP clients to bypass access control checks, potentially enabling unauthorized modification of directory entries.
Executive summary
A high-severity authorization bypass vulnerability in Red Hat Directory Server allows unauthenticated attackers to perform unauthorized directory operations.
Vulnerability
This is an improper authorization flaw (CWE-863) where the SELFDN ACI bind-rule evaluator incorrectly validates empty bind DNs. An unauthenticated attacker can exploit this logic error to bypass access control restrictions intended for authenticated users.
Business impact
The ability for unauthenticated users to modify or add directory entries poses a significant risk to organizational identity and access management. Because this vulnerability permits unauthorized data manipulation, it could be leveraged to escalate privileges or exfiltrate sensitive directory information, violating the integrity of the directory service. The CVSS score of 7.5 reflects the high impact on system integrity and the ease of exploitation given the lack of required authentication.
Remediation
Immediate Action: Update Red Hat Directory Server to the versions specified in the relevant Red Hat Security Advisories (RHSA-2026:64771, 64776, 64778, 64779, 64780, 64781, 64783, 64784) immediately.
Proactive Monitoring: Review LDAP access logs for anomalous bind attempts or unexpected modifications to directory entries from unknown or anonymous sources.
Compensating Controls: Implement strict network-level access controls to limit access to the LDAP service to trusted internal IP ranges, which reduces the potential attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a clear risk to the integrity of directory services, which often serve as the foundation for enterprise authentication. Given that patches are available across the affected RHEL and Directory Server releases, administrators must prioritize these updates to prevent potential unauthorized directory modifications. Failure to patch leaves the directory susceptible to manipulation by any network-adjacent, unauthenticated actor.
More Red Hat CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Red Hat would like to thank Gia Bui (yabeow) (Calif.io) for reporting this issue., per the CVE Program record.
- RHSA-2026:64771 Vendor advisory
- RHSA-2026:64776 Vendor advisory
- RHSA-2026:64778 Vendor advisory
- RHSA-2026:64779 Vendor advisory
- RHSA-2026:64780 Vendor advisory
- RHSA-2026:64781 Vendor advisory
- RHSA-2026:64783 Vendor advisory
- RHSA-2026:64784 Vendor advisory