Skip to content
Threat Feed

Product

389 Directory Server

5 briefs RSS
high advisory

Authentication Bypass in 389 Directory Server via SELFDN ACI

An authentication bypass vulnerability in 389 Directory Server allows unauthenticated LDAP clients to bypass access control rules by exploiting an error in the SELFDN ACI bind-rule evaluator.

389 Directory Server ldap authentication-bypass access-control
1t 1c
high advisory

Command Injection in 389 Directory Server Cockpit Console

A command injection vulnerability in the 389 Directory Server Cockpit console allows authenticated users with entry-creation privileges to achieve root-level command execution via crafted LDAP distinguished names.

389 Directory Server cve-2026-19843 command-injection privilege-escalation
2t 1c
low advisory

Denial of Service in 389 Directory Server via CVE-2026-18453

An unauthenticated remote attacker can crash the 389 Directory Server by sending crafted LDAP paged search requests, resulting in a denial of service condition.

389 Directory Server
1t 1c
critical advisory

Authentication Bypass in 389 Directory Server via SASL Bind State Confusion

A vulnerability in 389 Directory Server allows unauthenticated attackers to elevate privileges by exploiting state confusion during SASL authentication, leading to unauthorized Directory Manager access.

389 Directory Server authentication-bypass cve-2026-18922 privilege-escalation
1t 1c
critical advisory

Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw

An unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.

FreeIPA +2 identity-management authentication-bypass privilege-escalation ldap vulnerability cve linux
3t 3c updated