Description
In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)
Published: 2026-09-30
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Authentication bypass and potential denial of service via LDAPd
Action: Immediate Patch
AI Analysis

Impact

The flaw in ldapd causes delegated BSD authentication results to be correlated only by the LDAP child process client file descriptor and message ID. When a connection closes, a subsequent connection that reuses the same file descriptor and message ID can receive the earlier authentication result. Consequently, a remote attacker who can reach the LDAP server can complete a Bind as another identity, gaining unauthorized access. The vulnerability also includes a missing connection check that can lead to a NULL pointer dereference, which may crash ldapd and cause a denial of service.

Affected Systems

OpenBSD OpenBSD versions 7.8 before errata 057 and 7.9 before errata 021 are affected. The fork of ldapd is not enabled by default but may be used in custom configurations.

Risk and Exploitability

The CVSS score of 9.2 indicates a high severity vulnerability. The EPSS score is not available, but the lack of a KEV listing does not diminish the risk of exploitation. The likely attack vector is a network attacker able to contact ldapd, which is typically exposed on standard LDAP ports. Once a connection is reopened with the same file descriptor and message ID, the attacker can obtain a valid authentication result for an arbitrary identity, leading to privilege escalation. Administrative privileges or configuration errors that expose ldapd to the network would make exploitation easier.

Generated by OpenCVE AI on September 30, 2026 at 20:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply OpenBSD errata 057 to 7.8 or errata 021 to 7.9 to patch ldapd
  • If ldapd is not required, disable it or remove the service
  • As a temporary mitigation, restrict network access to the LDAP port using a firewall or access control list

Generated by OpenCVE AI on September 30, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title LDAP Authentication Bypass via Reused File Descriptor and Message ID in OpenBSD ldapd

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)
First Time appeared Openbsd
Openbsd openbsd
Weaknesses CWE-863
CPEs cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*
Vendors & Products Openbsd
Openbsd openbsd
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T19:55:54.044Z

Reserved: 2026-09-30T19:40:52.241Z

Link: CVE-2026-103547

cve-icon Vulnrichment

Updated: 2026-09-30T19:55:48.887Z

cve-icon NVD

Status : Received

Published: 2026-09-30T20:17:31.607

Modified: 2026-09-30T20:17:31.607

Link: CVE-2026-103547

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T21:00:09Z

Weaknesses