{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/389-project/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389_project:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-76560"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389 Directory Server"],"_cs_severities":["high"],"_cs_tags":["ldap","authentication-bypass","access-control"],"_cs_type":"advisory","_cs_vendors":["389 Project"],"content_html":"\u003cp\u003eCVE-2026-76560 is an authentication bypass vulnerability within the 389 Directory Server. The flaw resides in the SELFDN ACI (Access Control Instruction) bind-rule evaluator, which governs access based on whether the bind DN matches a value within the directory entry. When an anonymous LDAP client provides an empty bind DN, the evaluator incorrectly matches this against an empty stored attribute value.\u003c/p\u003e\n\u003cp\u003eThis logic error enables unauthenticated attackers to satisfy access control checks that are explicitly intended to be restricted to specific authenticated identities. If the directory contains entries with empty attributes targeted by a SELFDN-based ACI, an anonymous attacker can successfully perform unauthorized operations, including creating or modifying directory objects. This flaw bypasses fundamental authentication requirements, potentially leading to unauthorized data modification or administrative control over directory objects. Defenders should prioritize patching, as this vulnerability allows direct manipulation of directory contents without requiring any valid credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass security policies governing SELFDN-based access control. This can result in unauthorized modification or addition of directory entries, potentially impacting the integrity and availability of identity management services dependent on 389 Directory Server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all instances of 389 Directory Server to the version containing the security update for CVE-2026-76560. Review existing ACI configurations to determine if SELFDN is currently in use, as environments relying on these rules for sensitive operations are at highest risk of unauthorized modifications. Monitor LDAP access logs for successful operations originating from unauthenticated (anonymous) bind requests that interact with entries typically restricted to authenticated users.\u003c/p\u003e\n","date_modified":"2026-09-07T21:36:35Z","date_published":"2026-09-07T21:36:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-76560/","summary":"An authentication bypass vulnerability in 389 Directory Server allows unauthenticated LDAP clients to bypass access control rules by exploiting an error in the SELFDN ACI bind-rule evaluator.","title":"Authentication Bypass in 389 Directory Server via SELFDN ACI","url":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-76560/"}],"language":"en","title":"CraftedSignal Threat Feed - 389 Project","version":"https://jsonfeed.org/version/1.1"}