Description
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Published: 2026-10-01
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Disable StartTLS
AI Analysis

Impact

The flaw in 389-ds-base stems from the server retaining plaintext bytes that a client has already sent during a StartTLS upgrade. An on‑path attacker can inject a crafted LDAP message that is processed after TLS is established. If the injected message shares the same messageID as the client’s pending operation, the server returns the attacker’s response to the client, making a failed authentication appear to succeed. This effectively allows the attacker to authenticate as any user without valid credentials, a classic authentication bypass scenario described by CWE‑923.

Affected Systems

Affected systems include Red Hat Directory Server versions 11, 12, and 13, as well as Red Hat Enterprise Linux distributions 10, 6, 7, 8, and 9, which expose the vulnerable LDAP service on port 389.

Risk and Exploitability

The CVSS score of 9 indicates critical severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, but an attacker with the ability to interpose traffic on the LDAP port can exploit the buffer‑retention flaw easily. The attack requires only network position, not privileged access, and can be performed over standard LDAP traffic. Because no official patch exists, the exploit remains viable for the entire set of affected products unless mitigated.

Generated by OpenCVE AI on October 2, 2026 at 00:20 UTC.

Remediation

Vendor Workaround

Disable StartTLS on port 389 and require ldaps:// (port 636) instead, which has no cleartext prefix to inject into. No configuration-only mitigation fully closes the issue on port 389 while StartTLS remains enabled.


OpenCVE Recommended Actions

  • Disable StartTLS on port 389 and enforce the use of LDAPS (port 636), which does not use a cleartext prefix and cannot be exploited this way.
  • Configure all LDAP clients to connect directly to LDAPS on port 636 instead of using StartTLS on port 389.
  • If StartTLS must remain enabled for legacy reasons, isolate the LDAP service from external networks or block port 389 to prevent interception until a vendor fix is released.

Generated by OpenCVE AI on October 2, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 01 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Title 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result
First Time appeared Redhat
Redhat directory Server
Redhat enterprise Linux
Weaknesses CWE-923
CPEs cpe:/a:redhat:directory_server:11
cpe:/a:redhat:directory_server:12
cpe:/a:redhat:directory_server:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat directory Server
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Directory Server Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-02T00:36:18.261Z

Reserved: 2026-09-07T09:14:21.954Z

Link: CVE-2026-86345

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T00:17:04.180

Modified: 2026-10-02T00:17:04.180

Link: CVE-2026-86345

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-01T00:00:00Z

Links: CVE-2026-86345 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T00:30:16Z

Weaknesses
  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints