SASL PLAIN Oversight in OpenDJ Directory Service by OpenIdentityPlatform
CVE-2026-73644
9.6CRITICAL
What is CVE-2026-73644?
OpenDJ is a directory service compliant with LDAPv3. In versions prior to 5.1.2, a flaw existed in the SASL PLAIN authorization identity implementation. Specifically, the authorization handling did not correctly evaluate permissions for proxy authorizations when resolving external identities, allowing authenticated users with the PROXIED_AUTH privilege to assume other user identities outside of their permitted range. This security oversight has been addressed in version 5.1.2, which now returns INVALID_CREDENTIALS (49) early when a target authorization identity is inappropriate.
Affected Version(s)
OpenDJ < 5.1.2
