Description
A flaw in the libcurl SASL negotiation for LDAP authentication allows an
incomplete handshake sequence to be misinterpreted as a successful
cryptographic verification. An attacker executing a Man-in-the-Middle (MITM)
attack can inject a premature or shortcut response that bypasses complete peer
validation.
Published: 2026-09-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in libcurl’s SASL negotiation logic allows an attacker performing a man‑in‑the‑middle attack to inject a premature or shortcut response that the client interprets as a successful cryptographic verification. The incomplete handshake is thus treated as a valid authentication, enabling the attacker to bypass authentication controls and gain unauthorized access or impersonate a legitimate LDAP client.

Affected Systems

The vulnerability exists in the libcurl component used by the curl library. Devices or applications that rely on libcurl for LDAP authentication, particularly those enabling SASL negotiation, are at risk. Specific affected versions are not listed in the advisory, but any instance of libcurl that implements the vulnerable SASL code path is potentially impacted.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the overall exploitation probability cannot be quantified from these metrics. Nonetheless, the flaw permits a complete bypass of authentication once a MITM position is achieved, meaning that an attacker who can intercept or influence the LDAP traffic can achieve remote unauthenticated access. No public exploit is reported, but the attack path requires network-level access to mediate the handshake.

Generated by OpenCVE AI on September 6, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade libcurl to the latest patched version that includes the SASL handling fix.
  • If an upgrade is not feasible, disable SASL authentication or enforce TLS with client certificate verification to eliminate reliance on the vulnerable SASL negotiation.
  • Apply network controls to prevent MITM attacks, such as strict TLS pinning, enabling intrusion detection or blocking passive sniffing on the networks where LDAP traffic flows.

Generated by OpenCVE AI on September 6, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 06 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Curl
Curl curl
Vendors & Products Curl
Curl curl

Sun, 06 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sun, 06 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
Title OpenLDAP SASL authentication bypass
References

cve-icon MITRE

Status: PUBLISHED

Assigner: curl

Published:

Updated: 2026-09-06T17:47:01.951Z

Reserved: 2026-06-29T08:57:44.945Z

Link: CVE-2026-13608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-06T18:17:19.810

Modified: 2026-09-06T18:17:19.810

Link: CVE-2026-13608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T20:00:05Z

Weaknesses