389 DS LDAP Filter Injection via CleanAllRUV Replication Status-Check
CVE-2026-11770 Published on July 31, 2026
389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
Vulnerability Analysis
CVE-2026-11770 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public. 100 days later.
Weakness Type
What is a LDAP Injection Vulnerability?
The software constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
CVE-2026-11770 has been classified to as a LDAP Injection vulnerability or weakness.
Products Associated with CVE-2026-11770
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Directory Server 11.9 for RHEL 8:- Version 8100020260803140625.37ed7c03 and below * is unaffected.
- Version 0:3.2.0-9.el10_2 and below * is unaffected.
- Version 0:3.0.6-20.el10_0 and below * is unaffected.
- Version 0:1.3.11.1-14.el7_9 and below * is unaffected.
- Version 8100020260806150504.25e700aa and below * is unaffected.
- Version 8040020260803141511.96015a92 and below * is unaffected.
- Version 8040020260803141511.96015a92 and below * is unaffected.
- Version 8060020260806120442.824efc52 and below * is unaffected.
- Version 8060020260806120442.824efc52 and below * is unaffected.
- Version 8080020260806114228.6dbb3803 and below * is unaffected.
- Version 8080020260806114228.6dbb3803 and below * is unaffected.
- Version 0:2.8.0-9.el9_8 and below * is unaffected.
- Version 0:2.2.4-20.el9_2 and below * is unaffected.
- Version 0:2.4.5-27.el9_4 and below * is unaffected.
- Version 0:2.6.1-23.el9_6 and below * is unaffected.