Authorization Flaw in 389 Directory Server Allowing Unauthorized Operations
CVE-2026-19404

6.5MEDIUM

What is CVE-2026-19404?

An authorization flaw exists in 389 Directory Server, allowing unauthenticated remote attackers to execute CleanAllRUV and Abort CleanAllRUV operations when anonymous access is permitted. This default setting could enable unauthorized changes to replication metadata, including removal of replica IDs and purging of changelog records. Such actions can disrupt replication processes, leading to inconsistent or unavailable directories, thereby severely impacting system integrity and availability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Andrew Rukin (Arenadata) for reporting this issue.
.