{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/389-directory-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389_directory_server_project:389-ds-base:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-11774"},{"cvss":7.5,"id":"CVE-2026-18355"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389-ds-base"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["389 Directory Server"],"content_html":"\u003cp\u003eA heap buffer overflow vulnerability exists in the SASL I/O layer of 389 Directory Server (389-ds-base), specifically within the sasl_io_read_packet() function. The flaw occurs because the wrapped-record length read from the wire is insufficiently validated. When an attacker provides a small wire length (0, 1, or 2) during a SASL bind with integrity protection (SSF \u0026gt; 0), the application performs an unsigned subtraction underflow when calculating the buffer count. This logic error instructs the system to read approximately 4 GiB of data into a 1024-byte heap-allocated buffer.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows a remote authenticated attacker to trigger memory corruption, leading to a denial of service (DoS) or potentially remote code execution (RCE). This issue is distinct from the previously reported CVE-2026-11774, as the earlier mitigation only addressed upper-bound overflows and failed to account for these specific underflow scenarios.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this flaw can result in a crash of the 389 Directory Server process, causing service disruption. Furthermore, the ability to trigger a heap overflow with attacker-controlled content provides a pathway for remote code execution, which could lead to full system compromise of servers running 389-ds-base.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview security patches provided by the 389 Directory Server project and apply updates to 389-ds-base immediately to address CVE-2026-18355.\u003c/li\u003e\n\u003cli\u003eMonitor service logs for unexpected 389 Directory Server process crashes or restarts, which may indicate attempted exploitation.\u003c/li\u003e\n\u003cli\u003eRestrict access to Directory Server management interfaces to trusted administrative segments to reduce the risk of exploitation by unauthorized or partially authenticated entities.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T15:33:44Z","date_published":"2026-09-07T15:33:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-389-ds-heap-overflow/","summary":"A heap buffer overflow vulnerability in the SASL I/O layer of 389-ds-base allows a remote authenticated attacker to trigger an unsigned subtraction underflow and cause memory corruption.","title":"Heap Buffer Overflow in 389 Directory Server SASL I/O Layer","url":"https://feed.craftedsignal.io/briefs/2026-09-389-ds-heap-overflow/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389directoryserver:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18922"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389 Directory Server"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","cve-2026-18922","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["389 Directory Server"],"content_html":"\u003cp\u003eCVE-2026-18922 describes a critical authentication bypass vulnerability in 389 Directory Server. The issue stems from improper handling of identity state during SASL PLAIN authentication. When a bind operation fails, the server fails to properly clear the identity properties associated with the connection. A subsequent successful bind, using any SASL mechanism, allows the stale identity from the previous failed attempt to be incorrectly applied to the new security context. An attacker can deliberately trigger a failed SASL PLAIN bind as 'cn=Directory Manager' and then complete a second bind (such as an anonymous bind or a low-privileged account bind) to inherit the privileges of the identity used in the first failed attempt. This flaw grants an unauthorized attacker administrative access to the directory server without requiring valid credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the 389 Directory Server. An attacker can read, modify, or delete directory data, manage users, or alter security configurations, leading to a complete compromise of the identity store and downstream systems dependent on the directory for authentication or authorization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor 389 Directory Server access logs for unusual sequences of failed bind operations followed by immediate successful binds on the same connection.\u003c/li\u003e\n\u003cli\u003eReview directory server configuration for strict enforcement of authentication policies.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the vendor for 389 Directory Server to resolve the identity property handling flaw.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T15:32:59Z","date_published":"2026-09-07T15:32:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-389-directory-server-auth-bypass/","summary":"A vulnerability in 389 Directory Server allows unauthenticated attackers to elevate privileges by exploiting state confusion during SASL authentication, leading to unauthorized Directory Manager access.","title":"Authentication Bypass in 389 Directory Server via SASL Bind State Confusion","url":"https://feed.craftedsignal.io/briefs/2026-09-07-389-directory-server-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - 389 Directory Server","version":"https://jsonfeed.org/version/1.1"}