Description
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.
Published: 2026-08-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in 389 Directory Server allows CleanAllRUV and Abort CleanAllRUV replication‑maintenance extended operations to be executed without any authorization check. An unauthenticated client or an authenticated low‑privilege account can therefore remove a replica ID from the replication metadata, purge changelog records, or interrupt administrator‑initiated cleanup. The result is inconsistent or unavailable replication, which can undermine data consistency and availability for services relying on the directory.

Affected Systems

The vulnerability affects Red Hat Directory Server versions 11, 12, and 13, as well as Red Hat Enterprise Linux releases 6 through 10 that are shipped with that package. Any system running those products and providing LDAP replication services is potentially impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. Attackers can exploit this flaw remotely by connecting to the LDAP service; if nsslapd-allow-anonymous-access is enabled (the default) or by using any low‑privilege bound account, the vulnerable handlers can be invoked without further checks. The lack of an authorization guard makes the attack path straightforward, but the impact is limited to replication-related operations.

Generated by OpenCVE AI on August 10, 2026 at 11:52 UTC.

Remediation

Vendor Workaround

Set nsslapd-allow-anonymous-access to rootdse or off as an interim mitigation. Note this only blocks exploitation by fully unauthenticated (unbound) clients; any connection that has completed a successful bind with any DN, including a low-privileged account, still reaches the vulnerable handlers with no further authorization check. Restrict replication LDAP ports to trusted networks as defense in depth pending a code fix.


OpenCVE Recommended Actions

  • Apply Red Hat’s patch or upgrade to a patched version of Red Hat Directory Server
  • Set nsslapd-allow-anonymous-access to rootdse or disable the option to block unauthenticated access to the vulnerable handlers
  • Restrict LDAP replication ports to trusted networks as a defense‑in‑depth measure

Generated by OpenCVE AI on August 10, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.
Title 389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort cleanallruv replication maintenance
First Time appeared Redhat
Redhat directory Server
Redhat enterprise Linux
Weaknesses CWE-862
CPEs cpe:/a:redhat:directory_server:11
cpe:/a:redhat:directory_server:12
cpe:/a:redhat:directory_server:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat directory Server
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Redhat Directory Server Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-10T09:38:10.790Z

Reserved: 2026-08-10T07:55:45.246Z

Link: CVE-2026-19404

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T12:00:06Z

Weaknesses