BlackTree Security · Infrastructure · Automation · AI

One Failed Login Could Hand Attackers Full Control of 389 Directory Server

One rejected password should end an authentication attempt. In 389 Directory Server, it could instead leave the most powerful identity in the system waiting for the next bind on the same connection.

The 389 Directory Server CVE-2026-18922 flaw is a critical authentication failure with a preliminary CVSS 3.1 score of 9.8. Red Hat says a remote attacker can gain full Directory Manager privileges over an LDAPS connection without a valid account, user interaction or a non-default configuration.

The exploit sequence is unusually short. An attacker first attempts a SASL PLAIN bind as cn=Directory Manager using the wrong password. That bind fails, but a Cyrus SASL auxiliary property can retain the privileged identity. The attacker then performs a successful anonymous bind, or a bind with a valid low-privileged account, on the same connection. The server can install the stale Directory Manager identity and grant full authority to the second session.

The failed login is only the first half

This is not a claim that any failed Linux login creates an administrator. The weakness is specific to the way affected 389 Directory Server builds handle a failed SASL PLAIN bind and a later successful SASL bind on the same connection.

The first request plants the stale identity. The second request causes the server to reuse it. Red Hat’s zero-credential variant uses SASL ANONYMOUS for the second bind, while another variant uses the attacker’s own low-privileged account. Both depend on the failed PLAIN bind as Directory Manager occurring first.

QuestionCurrent answer
VulnerabilityCVE-2026-18922
ImpactFull Directory Manager privileges
Attack pathFailed SASL PLAIN bind, then a successful anonymous or low-privileged bind on the same connection
Authentication requiredNo valid account is required for the anonymous variant
SeverityRed Hat Critical, preliminary CVSS 3.1 score 9.8
Affected softwareMultiple supported Red Hat Directory Server and RHEL streams containing affected 389 Directory Server builds
Fixed softwareRed Hat has released corrected packages for multiple streams; administrators must match their exact product and lifecycle channel to the relevant erratum
WorkaroundExclude PLAIN from nsslapd-allowed-sasl-mechanisms if the mechanism is not required
Known exploitationNone reported in the public sources checked
Public proof of conceptNo credible public exploit was verified during publication checks

Full Directory Manager control is the whole directory

Directory Manager is not an ordinary LDAP user. It is the administrative identity that can bypass normal access controls and manage the directory’s contents and configuration. A successful takeover can expose identity data, allow records to be changed, create or elevate accounts, disrupt authentication-dependent services and erase information needed for an investigation.

The blast radius depends on how the directory is used. In an identity infrastructure, one directory may support employee authentication, applications, service accounts and administrative workflows. Compromising that trust anchor can become an access problem far beyond the directory server itself.

That is why the absence of confirmed exploitation does not make this a routine update. The flaw is remotely reachable, requires no valid credentials in its most serious form and crosses directly into the highest directory privilege.

Red Hat updates now cover multiple product streams

Red Hat’s CVE record was expanded on 8 September with corrected packages and security advisories for numerous supported channels. The list includes Red Hat Directory Server 11 and 12 streams, RHEL 8 application streams, RHEL 9, RHEL 10 and several extended-support variants. Red Hat Directory Server 13 is listed as unaffected.

The fixed build is not one universal upstream version. Red Hat backports security changes into product-specific packages. For example, the record lists 389-ds-base-3.2.0-10.el10_2 for RHEL 10, 389-ds-base-2.8.0-10.el9_8 for RHEL 9 and separate modular build identifiers for RHEL 8 and supported Directory Server channels.

Administrators should therefore use the Red Hat CVE page and the erratum for their exact subscription stream. Comparing only an upstream version string can produce the wrong answer when a vendor has backported the fix.

The mitigation removes the first step

If the update cannot be installed immediately, Red Hat recommends restricting nsslapd-allowed-sasl-mechanisms to the mechanisms the deployment actually needs and excluding PLAIN. The company gives GSSAPI, EXTERNAL and GSS-SPNEGO as examples of mechanisms that may remain where required.

Removing PLAIN blocks the failed Directory Manager bind that plants the stale identity. It prevents both the anonymous second-bind variant and the low-privileged-account variant described by Red Hat. This is a mitigation, not a substitute for installing the corrected package and verifying the running service after maintenance.

Any authentication change should be tested against real clients before broad deployment. If a business application depends on SASL PLAIN, isolating directory access and accelerating the vendor update may be safer than breaking authentication without a migration plan.

What 389 Directory Server operators should do now

  • Identify every 389 Directory Server and Red Hat Directory Server instance, including replicas, recovery systems and extended-support deployments.
  • Match each system to the exact Red Hat product stream and install the corrected package from the corresponding security advisory.
  • Confirm the running package and service build after maintenance rather than relying only on job completion.
  • If patching is delayed, exclude PLAIN from nsslapd-allowed-sasl-mechanisms where operationally possible and test dependent applications.
  • Restrict LDAPS access to the systems and networks that genuinely require it.
  • Review directory audit and access logs for unusual failed SASL PLAIN binds followed by anonymous or low-privileged binds on the same connection.
  • Inspect recent changes to privileged accounts, access-control instructions, replication agreements and directory configuration.
  • If compromise cannot be excluded, preserve logs and rotate credentials or secrets whose trust depends on the directory.

A stale identity should change the incident question

Installing the corrected package closes the vulnerable authentication path. It does not prove that the directory remained trustworthy before the update.

Where an affected LDAPS service was reachable from untrusted networks, the investigation should look beyond successful logins. The distinctive signal is a failed privileged PLAIN bind followed by an unrelated successful bind on the same connection. A conventional review that searches only for a successful Directory Manager password may miss the sequence entirely.

The security lesson is larger than one implementation bug. Authentication state must be cleared completely when a bind fails. A rejected credential should not leave anything behind that the next request can inherit.

389 Directory Server CVE-2026-18922 questions

Does the attack need a valid Directory Manager password?

No. Red Hat’s most serious sequence begins with an incorrect Directory Manager password and completes with an anonymous bind on the same connection.

Is the vulnerability being exploited?

The public sources checked do not report exploitation in the wild. That status is separate from the flaw’s technical severity and could change.

Is disabling SASL PLAIN enough?

It blocks the exploit sequence described by Red Hat when PLAIN is fully excluded, but it is a mitigation. Operators should still install the corrected package for their product stream.

Sources and publication details

  • Red Hat vulnerability advisory, made public 7 September 2026 at 14:33 Europe/Madrid. The product and fixed-package data was updated on 8 September 2026.
  • CVE Program vulnerability record, published 7 September 2026 at 16:14:53 Europe/Madrid and updated 8 September 2026 at 15:04:34 Europe/Madrid.
  • Red Hat Bugzilla 2511388, public issue record for the authentication-state flaw. The page does not provide a reliable public publication time.

Leave a Reply

Your email address will not be published. Required fields are marked *