Junglewise Threat Intelligence

CVE-2026-11785: 389 Directory Server type confusion in SSO token handler

CVE-2026-11785 · Severity: medium · CVSS 4.3 · Published 2026-06-09

Vendors: Red Hat.

Executive brief

389 Directory Server is an enterprise-grade LDAP server used for managing user identities and authentication. A security flaw in its Single Sign-On (SSO) token handler allows authenticated users to view internal memory addresses from the server's stack. While this does not directly expose user data, it provides attackers with technical details that can be used to bypass security protections like ASLR, making it easier to launch more complex follow-up attacks.

Technical details

A type confusion vulnerability exists in the 'extop_handle_ldapssotoken_request()' function within 'extendop.c' of 389-ds-base. The root cause is a programming error where a stack pointer is passed to 'ber_printf' using the 'i' format specifier, which expects an integer. This results in the low 32 bits of a stack address being encoded into LDAP extended operation responses. An authenticated, non-administrator attacker can exploit this to leak partial stack addresses, reducing the effectiveness of Address Space Layout Randomization (ASLR). The SSO token feature is reportedly enabled by default in some configurations.

Affected products

  • Red Hat 389 Directory Server (389-ds-base) unspecified

Timeline

  • 2026-06-05: disclosed: Initial report in Red Hat Bugzilla
  • 2026-06-09: advisory: CVE published by Red Hat

References