389 DS Stale Identity Exploit via SASL PLAIN Auth
CVE-2026-18922 Published on September 7, 2026
389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
Vulnerability Analysis
CVE-2026-18922 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Timeline
Reported to Red Hat.
Made public. 39 days later.
Weakness Type
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2026-18922 has been classified to as an authentification vulnerability or weakness.
Products Associated with CVE-2026-18922
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Directory Server 11.7 E4S for RHEL 8:- Version 8080020260903102346.f969626e and below * is unaffected.
- Version 8100020260904171440.37ed7c03 and below * is unaffected.
- Version 9020020260903155914.1674d574 and below * is unaffected.
- Version 9040020260903102623.1674d574 and below * is unaffected.
- Version 0:3.2.0-10.el10_2 and below * is unaffected.
- Version 0:3.0.6-21.el10_0 and below * is unaffected.
- Version 0:1.2.11.15-97.el6_10.1 and below * is unaffected.
- Version 0:1.3.11.1-15.el7_9 and below * is unaffected.
- Version 8100020260904155442.25e700aa and below * is unaffected.
- Version 8040020260901171549.96015a92 and below * is unaffected.
- Version 8040020260901171549.96015a92 and below * is unaffected.
- Version 8060020260901145727.824efc52 and below * is unaffected.
- Version 8060020260901145727.824efc52 and below * is unaffected.
- Version 8080020260831180218.6dbb3803 and below * is unaffected.
- Version 8080020260831180218.6dbb3803 and below * is unaffected.
- Version 0:2.8.0-10.el9_8 and below * is unaffected.
- Version 0:2.2.4-22.el9_2 and below * is unaffected.
- Version 0:2.4.5-29.el9_4 and below * is unaffected.
- Version 0:2.6.1-24.el9_6 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.