Product
Authentication Bypass in 389 Directory Server via SELFDN ACI
1 TTP 1 CVEAn authentication bypass vulnerability in 389 Directory Server allows unauthenticated LDAP clients to bypass access control rules by exploiting an error in the SELFDN ACI bind-rule evaluator.
Command Injection in 389 Directory Server Cockpit Console
2 TTPs 1 CVEA command injection vulnerability in the 389 Directory Server Cockpit console allows authenticated users with entry-creation privileges to achieve root-level command execution via crafted LDAP distinguished names.
Denial of Service in 389 Directory Server via CVE-2026-18453
1 TTP 1 CVEAn unauthenticated remote attacker can crash the 389 Directory Server by sending crafted LDAP paged search requests, resulting in a denial of service condition.
Authentication Bypass in 389 Directory Server via SASL Bind State Confusion
1 TTP 1 CVEA vulnerability in 389 Directory Server allows unauthenticated attackers to elevate privileges by exploiting state confusion during SASL authentication, leading to unauthorized Directory Manager access.
Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw
3 TTPs 3 CVEsAn unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.