LDAP Authentication Vulnerability in OpenBSD Products
CVE-2026-103547

9.2CRITICAL

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103547?

In OpenBSD versions 7.8 prior to errata 057 and 7.9 prior to errata 021, the ldapd service uses only the child process client file descriptor and LDAP message ID to correlate delegated BSD authentication results. This flawed correlation allows a remote attacker to exploit reused file descriptors and message IDs, potentially leading to unauthorized access by completing a Bind operation as a different user identity. Additionally, this vulnerability may result in a NULL pointer dereference under certain conditions, further posing risks to system stability and security. Note that ldapd is not enabled by default.

Affected Version(s)

OpenBSD 7.8

OpenBSD 7.9

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.