Unauth LDAP Client Bypasses SELFDN ACI in 389 DS
CVE-2026-76560 Published on September 7, 2026
389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
Vulnerability Analysis
CVE-2026-76560 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 23 days later.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-76560 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-76560
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Directory Server 11.7 E4S for RHEL 8:- Version 8080020260903102346.f969626e and below * is unaffected.
- Version 8100020260904171440.37ed7c03 and below * is unaffected.
- Version 9020020260903155914.1674d574 and below * is unaffected.
- Version 9040020260903102623.1674d574 and below * is unaffected.
- Version 0:3.2.0-10.el10_2 and below * is unaffected.
- Version 0:3.0.6-21.el10_0 and below * is unaffected.
- Version 0:1.3.11.1-15.el7_9 and below * is unaffected.
- Version 8100020260904155442.25e700aa and below * is unaffected.
- Version 8040020260901171549.96015a92 and below * is unaffected.
- Version 8040020260901171549.96015a92 and below * is unaffected.
- Version 8060020260901145727.824efc52 and below * is unaffected.
- Version 8060020260901145727.824efc52 and below * is unaffected.
- Version 8080020260831180218.6dbb3803 and below * is unaffected.
- Version 8080020260831180218.6dbb3803 and below * is unaffected.
- Version 0:2.8.0-10.el9_8 and below * is unaffected.
- Version 0:2.2.4-22.el9_2 and below * is unaffected.
- Version 0:2.4.5-29.el9_4 and below * is unaffected.
- Version 0:2.6.1-24.el9_6 and below * is unaffected.
- Version 1788851765 and below * is unaffected.