{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/389-directory-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389_project:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-76560"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389 Directory Server"],"_cs_severities":["high"],"_cs_tags":["ldap","authentication-bypass","access-control"],"_cs_type":"advisory","_cs_vendors":["389 Project"],"content_html":"\u003cp\u003eCVE-2026-76560 is an authentication bypass vulnerability within the 389 Directory Server. The flaw resides in the SELFDN ACI (Access Control Instruction) bind-rule evaluator, which governs access based on whether the bind DN matches a value within the directory entry. When an anonymous LDAP client provides an empty bind DN, the evaluator incorrectly matches this against an empty stored attribute value.\u003c/p\u003e\n\u003cp\u003eThis logic error enables unauthenticated attackers to satisfy access control checks that are explicitly intended to be restricted to specific authenticated identities. If the directory contains entries with empty attributes targeted by a SELFDN-based ACI, an anonymous attacker can successfully perform unauthorized operations, including creating or modifying directory objects. This flaw bypasses fundamental authentication requirements, potentially leading to unauthorized data modification or administrative control over directory objects. Defenders should prioritize patching, as this vulnerability allows direct manipulation of directory contents without requiring any valid credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass security policies governing SELFDN-based access control. This can result in unauthorized modification or addition of directory entries, potentially impacting the integrity and availability of identity management services dependent on 389 Directory Server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all instances of 389 Directory Server to the version containing the security update for CVE-2026-76560. Review existing ACI configurations to determine if SELFDN is currently in use, as environments relying on these rules for sensitive operations are at highest risk of unauthorized modifications. Monitor LDAP access logs for successful operations originating from unauthenticated (anonymous) bind requests that interact with entries typically restricted to authenticated users.\u003c/p\u003e\n","date_modified":"2026-09-07T21:36:35Z","date_published":"2026-09-07T21:36:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-76560/","summary":"An authentication bypass vulnerability in 389 Directory Server allows unauthenticated LDAP clients to bypass access control rules by exploiting an error in the SELFDN ACI bind-rule evaluator.","title":"Authentication Bypass in 389 Directory Server via SELFDN ACI","url":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-76560/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:red_hat:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.4,"id":"CVE-2026-19843"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389 Directory Server"],"_cs_severities":["high"],"_cs_tags":["cve-2026-19843","command-injection","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-19843 describes a critical command injection vulnerability in the 389 Directory Server's Cockpit 389 Console. The flaw stems from improper sanitization of LDAP entry distinguished names (DNs) when the console constructs and executes \u003ccode\u003eldapsearch\u003c/code\u003e commands. An attacker who has been delegated the authority to create or rename entries within the LDAP directory can inject arbitrary shell metacharacters into an entry's DN. When an administrator later logs into the Cockpit 389 Console and navigates to the view containing the malicious entry, the console's background process triggers the injection. Because the Cockpit 389 process operates with elevated permissions, the resulting command execution occurs with root privileges on the directory server host. This vulnerability effectively allows an attacker with low-level administrative access to escalate privileges to full system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains delegated LDAP write permissions for the target directory instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious Distinguished Name (DN) containing shell metacharacters such as backticks, semicolons, or pipe operators.\u003c/li\u003e\n\u003cli\u003eAttacker uses LDAP administrative tools to create or rename an existing entry using the crafted malicious DN.\u003c/li\u003e\n\u003cli\u003eAttacker waits for a system administrator to open the 389 Directory Server instance in the Cockpit 389 Console.\u003c/li\u003e\n\u003cli\u003eThe console interface iterates through directory entries and automatically executes a backend \u003ccode\u003eldapsearch\u003c/code\u003e call using the malicious DN string.\u003c/li\u003e\n\u003cli\u003eThe underlying shell interprets the injected metacharacters within the \u003ccode\u003eldapsearch\u003c/code\u003e command string.\u003c/li\u003e\n\u003cli\u003eThe system executes the injected payload as root, granting the attacker arbitrary code execution on the directory server host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full system compromise of the 389 Directory Server host, as the injected commands execute with root-level privileges. This enables attackers to exfiltrate the entire directory database, modify security credentials, install backdoors, or facilitate lateral movement within the network. The scope of impact is limited to organizations deploying 389 Directory Server with the Cockpit 389 Console management interface enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit existing LDAP entries for suspicious characters or unusually long strings in the 'distinguishedName' attribute using standard administrative tools.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on LDAP entry naming conventions to prevent the insertion of shell metacharacters.\u003c/li\u003e\n\u003cli\u003eRestrict delegation of entry creation or renaming privileges to a strictly controlled, minimal set of trusted users.\u003c/li\u003e\n\u003cli\u003eUpgrade 389 Directory Server and Cockpit 389 components to the patched version once released by the vendor.\u003c/li\u003e\n\u003cli\u003eMonitor host process-creation logs for \u003ccode\u003eldapsearch\u003c/code\u003e executions spawned by the Cockpit management user or web server process that contain suspicious shell arguments.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T15:34:00Z","date_published":"2026-09-07T15:34:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-19843/","summary":"A command injection vulnerability in the 389 Directory Server Cockpit console allows authenticated users with entry-creation privileges to achieve root-level command execution via crafted LDAP distinguished names.","title":"Command Injection in 389 Directory Server Cockpit Console","url":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-19843/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389directoryserver:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18453"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389 Directory Server"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-18453 is a vulnerability in the 389 Directory Server that allows for remote denial of service. The flaw stems from a missing NULL pointer check in the paged results handling logic within the op_shared_search function. An unauthenticated attacker can trigger this condition by sending a specially crafted sequence of LDAP search requests that utilize the USE_ONE_BACKEND control. When the server processes these requests in a specific manner, the lack of input validation results in a NULL pointer dereference, causing the LDAP server process to crash. This vulnerability is significant because it allows remote, unauthenticated actors to disrupt directory services with minimal interaction, potentially impacting authentication and authorization workflows that rely on the directory server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to a denial of service (DoS) of the 389 Directory Server. This impacts organizations relying on the server for centralized identity management, potentially preventing user authentication, service access, and administrative operations. The severity is assessed as high due to the ease of remote execution without authentication requirements.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch 389 Directory Server to the version containing the fix for CVE-2026-18453.\u003c/li\u003e\n\u003cli\u003eMonitor LDAP traffic for excessive or malformed search requests using the USE_ONE_BACKEND control in the request payload.\u003c/li\u003e\n\u003cli\u003eLimit network access to the LDAP service to trusted subnets and IP addresses to prevent unauthenticated remote access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T15:33:51Z","date_published":"2026-09-07T15:33:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-389-directory-server-dos/","summary":"An unauthenticated remote attacker can crash the 389 Directory Server by sending crafted LDAP paged search requests, resulting in a denial of service condition.","title":"Denial of Service in 389 Directory Server via CVE-2026-18453","url":"https://feed.craftedsignal.io/briefs/2026-09-389-directory-server-dos/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389directoryserver:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18922"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389 Directory Server"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","cve-2026-18922","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["389 Directory Server"],"content_html":"\u003cp\u003eCVE-2026-18922 describes a critical authentication bypass vulnerability in 389 Directory Server. The issue stems from improper handling of identity state during SASL PLAIN authentication. When a bind operation fails, the server fails to properly clear the identity properties associated with the connection. A subsequent successful bind, using any SASL mechanism, allows the stale identity from the previous failed attempt to be incorrectly applied to the new security context. An attacker can deliberately trigger a failed SASL PLAIN bind as 'cn=Directory Manager' and then complete a second bind (such as an anonymous bind or a low-privileged account bind) to inherit the privileges of the identity used in the first failed attempt. This flaw grants an unauthorized attacker administrative access to the directory server without requiring valid credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the 389 Directory Server. An attacker can read, modify, or delete directory data, manage users, or alter security configurations, leading to a complete compromise of the identity store and downstream systems dependent on the directory for authentication or authorization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor 389 Directory Server access logs for unusual sequences of failed bind operations followed by immediate successful binds on the same connection.\u003c/li\u003e\n\u003cli\u003eReview directory server configuration for strict enforcement of authentication policies.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the vendor for 389 Directory Server to resolve the identity property handling flaw.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T15:32:59Z","date_published":"2026-09-07T15:32:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-389-directory-server-auth-bypass/","summary":"A vulnerability in 389 Directory Server allows unauthenticated attackers to elevate privileges by exploiting state confusion during SASL authentication, leading to unauthorized Directory Manager access.","title":"Authentication Bypass in 389 Directory Server via SASL Bind State Confusion","url":"https://feed.craftedsignal.io/briefs/2026-09-07-389-directory-server-auth-bypass/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-76578"},{"cvss":7.5,"id":"CVE-2026-76560"},{"cvss":8.1,"id":"CVE-2026-79678"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FreeIPA (all versions)","FreeIPA","389 Directory Server"],"_cs_severities":["critical"],"_cs_tags":["identity-management","authentication-bypass","privilege-escalation","ldap","vulnerability","cve","linux"],"_cs_type":"advisory","_cs_vendors":["FreeIPA"],"content_html":"\u003cp\u003eA critical vulnerability (CVE-2026-76578) exists within FreeIPA's self-managed OTP token mechanism. The Access Control Instructions (ACI) associated with self-managed tokens fail to enforce authentication requirements and do not validate attributes added alongside a token entry. An unauthenticated attacker can interact with the LDAP interface to inject arbitrary attributes. When chained with a related, independently tracked vulnerability in the underlying 389 Directory Server's ACI evaluation logic, the attacker can successfully create a malicious Kerberos principal and append it to the administrator group. This enables full administrative control over the FreeIPA environment, including directory management and potential impact on integrated IdM services in SID-enabled deployments. Because the attack originates from the network-accessible LDAP service without requiring prior authentication, it poses a severe risk to identity infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify accessible LDAP interfaces (port 389/636) on the target FreeIPA instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious LDAP packet targeting the self-managed OTP token endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker bypasses missing authentication checks within the vulnerable OTP ACI implementation.\u003c/li\u003e\n\u003cli\u003eAttacker injects arbitrary attributes into the directory entry, bypassing existing input validation constraints.\u003c/li\u003e\n\u003cli\u003eAttacker leverages a secondary ACI evaluation vulnerability in the underlying directory server to elevate privileges for the injected principal.\u003c/li\u003e\n\u003cli\u003eAttacker creates an unauthorized Kerberos principal and associates it with the administrator group in the LDAP backend.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates as the newly created administrative principal to obtain a legitimate Kerberos ticket-granting ticket (TGT).\u003c/li\u003e\n\u003cli\u003eAttacker performs administrative operations, such as user modification or full directory exfiltration, gaining total control over IdM services.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in complete administrative compromise of the FreeIPA environment. An attacker can gain unauthorized membership in the administrator group, allowing them to modify sensitive identity records, access secret keys, and manage all IdM services. In deployments where SID mapping is enabled, this compromise may extend to integrated Windows environments and other services relying on the IdM instance, leading to large-scale credential theft and persistent unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately audit all FreeIPA and underlying 389 Directory Server installations to confirm version compatibility with patches for CVE-2026-76578.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall rules to restrict network-based LDAP (389/636) access to authorized management subnets only.\u003c/li\u003e\n\u003cli\u003eMonitor directory server access logs for anomalous LDAP bind or entry modification attempts targeting OTP token attributes or unauthorized additions to the admin group.\u003c/li\u003e\n\u003cli\u003eReview administrative group membership logs for recently created or unknown Kerberos principals.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-08T11:45:35Z","date_published":"2026-09-07T13:36:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-freeipa-otp-bypass/","summary":"An unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.","title":"Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw","url":"https://feed.craftedsignal.io/briefs/2026-09-freeipa-otp-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - 389 Directory Server","version":"https://jsonfeed.org/version/1.1"}