Junglewise Threat Intelligence

CVE-2026-18922: 389 Directory Server SASL PLAIN authentication privilege escalation

CVE-2026-18922 · Severity: critical · CVSS 9.8 · Published 2026-09-07

Technologies: 389 Directory Server.

Executive brief

389 Directory Server is an LDAP directory service used to store and manage user identity and access information across enterprise networks. A flaw in SASL authentication allows attackers to escalate privileges to the Directory Manager (root-level access) by exploiting stale authentication state from failed login attempts. An attacker can complete a low-privilege or anonymous login after a failed high-privilege attempt, gaining full administrative control over the directory and all user data without valid credentials.

Technical details

The vulnerability is an authentication bypass in 389 Directory Server's SASL PLAIN implementation. During SASL PLAIN authentication, a stale identity from a failed bind attempt (e.g., failed Directory Manager bind with incorrect password) is retained in a Cyrus SASL auxiliary property and can be incorrectly applied to a subsequent successful bind on the same connection, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with wrong credentials, then complete either a SASL ANONYMOUS bind or a valid low-privileged account's successful bind on the same connection, causing the server to incorrectly grant Directory Manager authority. The vulnerability is network-accessible and requires no authentication to initiate; a fix is available in 389-ds-base version 1.3.11.1-15.el7_9.

Affected products

  • 389 Directory Server prior to 1.3.11.1-15.el7_9

Timeline

  • 2026-09-07: disclosed
  • 2026-09-08: patched

References