Executive brief
389 Directory Server is an open-source LDAP directory service used to store and manage user identities and authentication data in enterprise environments. This vulnerability allows an unauthenticated attacker to bypass access control rules designed to restrict directory operations to specific authenticated users, potentially enabling unauthorized modifications to sensitive directory entries such as user accounts or group memberships.
Technical details
The SELFDN ACI (Access Control Instruction) bind-rule evaluator in 389 Directory Server contains a logic error that incorrectly matches an anonymous LDAP client's empty bind DN (distinguished name) against empty stored attribute values. This allows unauthenticated clients to satisfy access control checks that should require a matching authenticated identity. The vulnerability affects LDAP operations (such as add, modify, delete) protected by SELFDN-based ACIs. An attacker can exploit this via a network LDAP connection without authentication to perform privileged directory operations. Patches addressing this issue are expected from Red Hat.
Affected products
- 389 Project 389 Directory Server
Timeline
- 2026-09-07: disclosed