CVE-2026-86345

Description

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.

Statement

This flaw is rated Moderate rather than Critical or Important, despite a CVSS base score of 9.0. Exploitation requires an attacker to hold an active on-path (man-in-the-middle) position on the network segment between an LDAP client and the server at the moment StartTLS is negotiated -- a materially harder precondition than a purely remote, unauthenticated attack, and one that rules out the ease-of-exploitation bar Critical requires. The outcome is also not arbitrary code execution: exploitation causes a client-side application (e.g. a PAM module) to incorrectly treat a failed authentication attempt as successful, granting access through that application's own, legitimate, pre-existing login mechanism rather than through execution of attacker-supplied code. 389-ds-base itself is not compromised by this flaw -- the server suffers no privilege escalation and no data exfiltration beyond what an anonymous bind could already obtain; the security impact is entirely realized in separate, downstream client applications that trust the LDAP bind result.

Mitigation

Disable StartTLS on port 389 and require ldaps:// (port 636) instead, which has no cleartext prefix to inject into. No configuration-only mitigation fully closes the issue on port 389 while StartTLS remains enabled.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score9N/A9
Attack VectorNetworkN/ANetwork
Attack ComplexityHighN/AHigh
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeChangedN/AChanged
ConfidentialityHighN/AHigh
Integrity ImpactHighN/AHigh
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Red Hat CVSS v3 Score Explanation

Scored against the impacted component (the downstream client/PAM authentication decision, per Scope Changed) rather than 389-ds-base itself, which suffers no server-side privilege gain or data exfiltration. AC:H reflects the required active on-path (MITM) position, precise messageID prediction, and forcing turbo mode. Presented Impact is MODERATE rather than the 9.0 score-range default of Critical/Important -- precedent: CVE-2024-3596 (Blast-RADIUS), same S:C/C:H/I:H/A:H/9.0 shape, rated Important by Red Hat citing the same MITM attack-surface limitation; here the additional non-arbitrary-code-execution nature of the outcome (authentication bypass via the account's own legitimate login mechanism, not attacker-controlled code) supports a further reduction to Moderate.

Understanding the Weakness (CWE)

Integrity,Confidentiality

Technical Impact: Gain Privileges or Assume Identity

If an attacker can spoof the endpoint, the attacker gains all the privileges that were intended for the original endpoint.

Acknowledgements

Red Hat would like to thank xclow3n for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.