LDAP Authentication Vulnerability in OpenBSD Products
CVE-2026-103547
9.2CRITICAL
What is CVE-2026-103547?
In OpenBSD versions 7.8 prior to errata 057 and 7.9 prior to errata 021, the ldapd service uses only the child process client file descriptor and LDAP message ID to correlate delegated BSD authentication results. This flawed correlation allows a remote attacker to exploit reused file descriptors and message IDs, potentially leading to unauthorized access by completing a Bind operation as a different user identity. Additionally, this vulnerability may result in a NULL pointer dereference under certain conditions, further posing risks to system stability and security. Note that ldapd is not enabled by default.
Affected Version(s)
OpenBSD 7.8
OpenBSD 7.9