<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>389 Directory Server - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/389-directory-server/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 07 Sep 2026 21:36:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/389-directory-server/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in 389 Directory Server via SELFDN ACI</title><link>https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-76560/</link><pubDate>Mon, 07 Sep 2026 21:36:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-76560/</guid><description>An authentication bypass vulnerability in 389 Directory Server allows unauthenticated LDAP clients to bypass access control rules by exploiting an error in the SELFDN ACI bind-rule evaluator.</description><content:encoded><![CDATA[<p>CVE-2026-76560 is an authentication bypass vulnerability within the 389 Directory Server. The flaw resides in the SELFDN ACI (Access Control Instruction) bind-rule evaluator, which governs access based on whether the bind DN matches a value within the directory entry. When an anonymous LDAP client provides an empty bind DN, the evaluator incorrectly matches this against an empty stored attribute value.</p>
<p>This logic error enables unauthenticated attackers to satisfy access control checks that are explicitly intended to be restricted to specific authenticated identities. If the directory contains entries with empty attributes targeted by a SELFDN-based ACI, an anonymous attacker can successfully perform unauthorized operations, including creating or modifying directory objects. This flaw bypasses fundamental authentication requirements, potentially leading to unauthorized data modification or administrative control over directory objects. Defenders should prioritize patching, as this vulnerability allows direct manipulation of directory contents without requiring any valid credentials.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to bypass security policies governing SELFDN-based access control. This can result in unauthorized modification or addition of directory entries, potentially impacting the integrity and availability of identity management services dependent on 389 Directory Server.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all instances of 389 Directory Server to the version containing the security update for CVE-2026-76560. Review existing ACI configurations to determine if SELFDN is currently in use, as environments relying on these rules for sensitive operations are at highest risk of unauthorized modifications. Monitor LDAP access logs for successful operations originating from unauthenticated (anonymous) bind requests that interact with entries typically restricted to authenticated users.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ldap</category><category>authentication-bypass</category><category>access-control</category></item><item><title>Command Injection in 389 Directory Server Cockpit Console</title><link>https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-19843/</link><pubDate>Mon, 07 Sep 2026 15:34:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-19843/</guid><description>A command injection vulnerability in the 389 Directory Server Cockpit console allows authenticated users with entry-creation privileges to achieve root-level command execution via crafted LDAP distinguished names.</description><content:encoded><![CDATA[<p>CVE-2026-19843 describes a critical command injection vulnerability in the 389 Directory Server's Cockpit 389 Console. The flaw stems from improper sanitization of LDAP entry distinguished names (DNs) when the console constructs and executes <code>ldapsearch</code> commands. An attacker who has been delegated the authority to create or rename entries within the LDAP directory can inject arbitrary shell metacharacters into an entry's DN. When an administrator later logs into the Cockpit 389 Console and navigates to the view containing the malicious entry, the console's background process triggers the injection. Because the Cockpit 389 process operates with elevated permissions, the resulting command execution occurs with root privileges on the directory server host. This vulnerability effectively allows an attacker with low-level administrative access to escalate privileges to full system compromise.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker obtains delegated LDAP write permissions for the target directory instance.</li>
<li>Attacker crafts a malicious Distinguished Name (DN) containing shell metacharacters such as backticks, semicolons, or pipe operators.</li>
<li>Attacker uses LDAP administrative tools to create or rename an existing entry using the crafted malicious DN.</li>
<li>Attacker waits for a system administrator to open the 389 Directory Server instance in the Cockpit 389 Console.</li>
<li>The console interface iterates through directory entries and automatically executes a backend <code>ldapsearch</code> call using the malicious DN string.</li>
<li>The underlying shell interprets the injected metacharacters within the <code>ldapsearch</code> command string.</li>
<li>The system executes the injected payload as root, granting the attacker arbitrary code execution on the directory server host.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full system compromise of the 389 Directory Server host, as the injected commands execute with root-level privileges. This enables attackers to exfiltrate the entire directory database, modify security credentials, install backdoors, or facilitate lateral movement within the network. The scope of impact is limited to organizations deploying 389 Directory Server with the Cockpit 389 Console management interface enabled.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Audit existing LDAP entries for suspicious characters or unusually long strings in the 'distinguishedName' attribute using standard administrative tools.</li>
<li>Implement strict input validation on LDAP entry naming conventions to prevent the insertion of shell metacharacters.</li>
<li>Restrict delegation of entry creation or renaming privileges to a strictly controlled, minimal set of trusted users.</li>
<li>Upgrade 389 Directory Server and Cockpit 389 components to the patched version once released by the vendor.</li>
<li>Monitor host process-creation logs for <code>ldapsearch</code> executions spawned by the Cockpit management user or web server process that contain suspicious shell arguments.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-19843</category><category>command-injection</category><category>privilege-escalation</category></item><item><title>Denial of Service in 389 Directory Server via CVE-2026-18453</title><link>https://feed.craftedsignal.io/briefs/2026-09-389-directory-server-dos/</link><pubDate>Mon, 07 Sep 2026 15:33:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-389-directory-server-dos/</guid><description>An unauthenticated remote attacker can crash the 389 Directory Server by sending crafted LDAP paged search requests, resulting in a denial of service condition.</description><content:encoded><![CDATA[<p>CVE-2026-18453 is a vulnerability in the 389 Directory Server that allows for remote denial of service. The flaw stems from a missing NULL pointer check in the paged results handling logic within the op_shared_search function. An unauthenticated attacker can trigger this condition by sending a specially crafted sequence of LDAP search requests that utilize the USE_ONE_BACKEND control. When the server processes these requests in a specific manner, the lack of input validation results in a NULL pointer dereference, causing the LDAP server process to crash. This vulnerability is significant because it allows remote, unauthenticated actors to disrupt directory services with minimal interaction, potentially impacting authentication and authorization workflows that rely on the directory server.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to a denial of service (DoS) of the 389 Directory Server. This impacts organizations relying on the server for centralized identity management, potentially preventing user authentication, service access, and administrative operations. The severity is assessed as high due to the ease of remote execution without authentication requirements.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch 389 Directory Server to the version containing the fix for CVE-2026-18453.</li>
<li>Monitor LDAP traffic for excessive or malformed search requests using the USE_ONE_BACKEND control in the request payload.</li>
<li>Limit network access to the LDAP service to trusted subnets and IP addresses to prevent unauthenticated remote access.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item><item><title>Authentication Bypass in 389 Directory Server via SASL Bind State Confusion</title><link>https://feed.craftedsignal.io/briefs/2026-09-07-389-directory-server-auth-bypass/</link><pubDate>Mon, 07 Sep 2026 15:32:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-07-389-directory-server-auth-bypass/</guid><description>A vulnerability in 389 Directory Server allows unauthenticated attackers to elevate privileges by exploiting state confusion during SASL authentication, leading to unauthorized Directory Manager access.</description><content:encoded><![CDATA[<p>CVE-2026-18922 describes a critical authentication bypass vulnerability in 389 Directory Server. The issue stems from improper handling of identity state during SASL PLAIN authentication. When a bind operation fails, the server fails to properly clear the identity properties associated with the connection. A subsequent successful bind, using any SASL mechanism, allows the stale identity from the previous failed attempt to be incorrectly applied to the new security context. An attacker can deliberately trigger a failed SASL PLAIN bind as 'cn=Directory Manager' and then complete a second bind (such as an anonymous bind or a low-privileged account bind) to inherit the privileges of the identity used in the first failed attempt. This flaw grants an unauthorized attacker administrative access to the directory server without requiring valid credentials.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full administrative control over the 389 Directory Server. An attacker can read, modify, or delete directory data, manage users, or alter security configurations, leading to a complete compromise of the identity store and downstream systems dependent on the directory for authentication or authorization.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor 389 Directory Server access logs for unusual sequences of failed bind operations followed by immediate successful binds on the same connection.</li>
<li>Review directory server configuration for strict enforcement of authentication policies.</li>
<li>Apply patches provided by the vendor for 389 Directory Server to resolve the identity property handling flaw.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve-2026-18922</category><category>privilege-escalation</category></item><item><title>Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw</title><link>https://feed.craftedsignal.io/briefs/2026-09-freeipa-otp-bypass/</link><pubDate>Mon, 07 Sep 2026 13:36:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-freeipa-otp-bypass/</guid><description>An unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.</description><content:encoded><![CDATA[<p>A critical vulnerability (CVE-2026-76578) exists within FreeIPA's self-managed OTP token mechanism. The Access Control Instructions (ACI) associated with self-managed tokens fail to enforce authentication requirements and do not validate attributes added alongside a token entry. An unauthenticated attacker can interact with the LDAP interface to inject arbitrary attributes. When chained with a related, independently tracked vulnerability in the underlying 389 Directory Server's ACI evaluation logic, the attacker can successfully create a malicious Kerberos principal and append it to the administrator group. This enables full administrative control over the FreeIPA environment, including directory management and potential impact on integrated IdM services in SID-enabled deployments. Because the attack originates from the network-accessible LDAP service without requiring prior authentication, it poses a severe risk to identity infrastructure.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify accessible LDAP interfaces (port 389/636) on the target FreeIPA instance.</li>
<li>Attacker crafts a malicious LDAP packet targeting the self-managed OTP token endpoint.</li>
<li>Attacker bypasses missing authentication checks within the vulnerable OTP ACI implementation.</li>
<li>Attacker injects arbitrary attributes into the directory entry, bypassing existing input validation constraints.</li>
<li>Attacker leverages a secondary ACI evaluation vulnerability in the underlying directory server to elevate privileges for the injected principal.</li>
<li>Attacker creates an unauthorized Kerberos principal and associates it with the administrator group in the LDAP backend.</li>
<li>Attacker authenticates as the newly created administrative principal to obtain a legitimate Kerberos ticket-granting ticket (TGT).</li>
<li>Attacker performs administrative operations, such as user modification or full directory exfiltration, gaining total control over IdM services.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in complete administrative compromise of the FreeIPA environment. An attacker can gain unauthorized membership in the administrator group, allowing them to modify sensitive identity records, access secret keys, and manage all IdM services. In deployments where SID mapping is enabled, this compromise may extend to integrated Windows environments and other services relying on the IdM instance, leading to large-scale credential theft and persistent unauthorized access.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately audit all FreeIPA and underlying 389 Directory Server installations to confirm version compatibility with patches for CVE-2026-76578.</li>
<li>Implement strict firewall rules to restrict network-based LDAP (389/636) access to authorized management subnets only.</li>
<li>Monitor directory server access logs for anomalous LDAP bind or entry modification attempts targeting OTP token attributes or unauthorized additions to the admin group.</li>
<li>Review administrative group membership logs for recently created or unknown Kerberos principals.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>identity-management</category><category>authentication-bypass</category><category>privilege-escalation</category><category>ldap</category><category>vulnerability</category><category>cve</category><category>linux</category></item></channel></rss>