Authentication Flaw in 389 Directory Server by Red Hat
CVE-2026-18651

5.4MEDIUM

What is CVE-2026-18651?

A security weakness has been identified in the 389 Directory Server, where during the SASL PLAIN authentication process, the server sets the connection-level bind credentials before verifying whether the account is locked. If an account is found to be administratively locked, the initial authentication appears to fail for the client. However, the established authenticated state remains active, allowing continued interaction with the server using the locked account's privileges. This behavior undermines the effectiveness of account lock mechanisms intended for access control.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Andrew Rukin (Arenadata) and Chris Jarrett-Davies (OpenAI Security Research) for reporting this issue.
.