LDAP Vulnerability in 389 Directory Server from Red Hat
CVE-2026-76560
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-76560?
A security flaw exists in the 389 Directory Server where the SELFDN ACI bind-rule evaluator improperly allows an anonymous LDAP client to match an empty bind DN against a stored empty attribute. This misconfiguration permits an unauthenticated client to pass access control checks, granting unauthorized operations such as adding or modifying directory entries, which should be restricted to specific authenticated users. Addressing this vulnerability is critical to maintaining the integrity of directory access controls in a secure environment.
Affected Version(s)
Red Hat Directory Server 11.7 E4S for RHEL 8 8080020260903102346.f969626e
Red Hat Directory Server 11.9 for RHEL 8 8100020260904171440.37ed7c03
Red Hat Directory Server 12.2 E4S for RHEL 9 9020020260903155914.1674d574
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved