Junglewise Threat Intelligence

CVE-2026-78701: 389 Directory Server SASL UNBIND denial of service

CVE-2026-78701 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: 389 Project 389 Directory Server.

Executive brief

389 Directory Server is an open-source LDAP directory service used to manage user identities and authentication in enterprise environments. A vulnerability in its SASL UNBIND process allows authenticated attackers to send malicious requests that cause connections to hang, consuming server resources and disrupting service availability for legitimate users.

Technical details

The vulnerability exists in the Simple Authentication and Security Layer (SASL) UNBIND process in 389-ds-base. An authenticated remote attacker can craft a specially designed request that causes a connection to stall, triggering resource exhaustion on the server. This leads to a denial of service condition. Authentication is a precondition—the attacker must first establish a valid authenticated session to exploit this flaw. The attack vector is network-based and does not require user interaction beyond the attacker's ability to send the crafted request.

Affected products

  • 389 Project 389 Directory Server <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References