{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18922/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389directoryserver:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18922"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389 Directory Server"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","cve-2026-18922","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["389 Directory Server"],"content_html":"\u003cp\u003eCVE-2026-18922 describes a critical authentication bypass vulnerability in 389 Directory Server. The issue stems from improper handling of identity state during SASL PLAIN authentication. When a bind operation fails, the server fails to properly clear the identity properties associated with the connection. A subsequent successful bind, using any SASL mechanism, allows the stale identity from the previous failed attempt to be incorrectly applied to the new security context. An attacker can deliberately trigger a failed SASL PLAIN bind as 'cn=Directory Manager' and then complete a second bind (such as an anonymous bind or a low-privileged account bind) to inherit the privileges of the identity used in the first failed attempt. This flaw grants an unauthorized attacker administrative access to the directory server without requiring valid credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the 389 Directory Server. An attacker can read, modify, or delete directory data, manage users, or alter security configurations, leading to a complete compromise of the identity store and downstream systems dependent on the directory for authentication or authorization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor 389 Directory Server access logs for unusual sequences of failed bind operations followed by immediate successful binds on the same connection.\u003c/li\u003e\n\u003cli\u003eReview directory server configuration for strict enforcement of authentication policies.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the vendor for 389 Directory Server to resolve the identity property handling flaw.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T15:32:59Z","date_published":"2026-09-07T15:32:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-389-directory-server-auth-bypass/","summary":"A vulnerability in 389 Directory Server allows unauthenticated attackers to elevate privileges by exploiting state confusion during SASL authentication, leading to unauthorized Directory Manager access.","title":"Authentication Bypass in 389 Directory Server via SASL Bind State Confusion","url":"https://feed.craftedsignal.io/briefs/2026-09-07-389-directory-server-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18922","version":"https://jsonfeed.org/version/1.1"}