CVE-2026-86345
Description
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Statement
This flaw is rated Moderate rather than Critical or Important, despite a CVSS base score of 9.0. Exploitation requires an attacker to hold an active on-path (man-in-the-middle) position on the network segment between an LDAP client and the server at the moment StartTLS is negotiated -- a materially harder precondition than a purely remote, unauthenticated attack, and one that rules out the ease-of-exploitation bar Critical requires. The outcome is also not arbitrary code execution: exploitation causes a client-side application (e.g. a PAM module) to incorrectly treat a failed authentication attempt as successful, granting access through that application's own, legitimate, pre-existing login mechanism rather than through execution of attacker-supplied code. 389-ds-base itself is not compromised by this flaw -- the server suffers no privilege escalation and no data exfiltration beyond what an anonymous bind could already obtain; the security impact is entirely realized in separate, downstream client applications that trust the LDAP bind result.
Mitigation
Disable StartTLS on port 389 and require ldaps:// (port 636) instead, which has no cleartext prefix to inject into. No configuration-only mitigation fully closes the issue on port 389 while StartTLS remains enabled.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 9 | N/A | 9 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Changed | N/A | Changed |
| Confidentiality | High | N/A | High |
| Integrity Impact | High | N/A | High |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Red Hat CVSS v3 Score Explanation
Scored against the impacted component (the downstream client/PAM authentication decision, per Scope Changed) rather than 389-ds-base itself, which suffers no server-side privilege gain or data exfiltration. AC:H reflects the required active on-path (MITM) position, precise messageID prediction, and forcing turbo mode. Presented Impact is MODERATE rather than the 9.0 score-range default of Critical/Important -- precedent: CVE-2024-3596 (Blast-RADIUS), same S:C/C:H/I:H/A:H/9.0 shape, rated Important by Red Hat citing the same MITM attack-surface limitation; here the additional non-arbitrary-code-execution nature of the outcome (authentication bypass via the account's own legitimate login mechanism, not attacker-controlled code) supports a further reduction to Moderate.
Understanding the Weakness (CWE)
Integrity,Confidentiality
Technical Impact: Gain Privileges or Assume Identity
If an attacker can spoof the endpoint, the attacker gains all the privileges that were intended for the original endpoint.
Acknowledgements
Red Hat would like to thank xclow3n for reporting this issue.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.