SASL PLAIN Oversight in OpenDJ Directory Service by OpenIdentityPlatform
CVE-2026-73644

9.6CRITICAL

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73644?

OpenDJ is a directory service compliant with LDAPv3. In versions prior to 5.1.2, a flaw existed in the SASL PLAIN authorization identity implementation. Specifically, the authorization handling did not correctly evaluate permissions for proxy authorizations when resolving external identities, allowing authenticated users with the PROXIED_AUTH privilege to assume other user identities outside of their permitted range. This security oversight has been addressed in version 5.1.2, which now returns INVALID_CREDENTIALS (49) early when a target authorization identity is inappropriate.

Affected Version(s)

OpenDJ < 5.1.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.