A critical flaw in 389-ds-base (CVSS 9.0) lets an on-path attacker inject plaintext LDAP data during a StartTLS upgrade. This can make a client application treat a failed bind as a successful one.
What Is It
CVE-2026-86345 is a flaw in 389-ds-base, the LDAP server behind Red Hat Directory Server. When a client negotiates StartTLS, the server keeps any plaintext bytes it has already buffered from that connection instead of discarding them. An on-path attacker can use this to inject a crafted LDAP message, which the server processes after the TLS upgrade. The injected message's messageID collides with the client's own pending operation. As a result, the server sends the response to the injected message to the client in place of the response the client was waiting for.
Red Hat classifies the weakness as CWE-923. NVD lists the record's status as "Received".
Why It Matters
According to the description, the practical impact is authentication confusion: a client application can treat a failed bind attempt as successful. Directory servers often handle authentication for other systems, so a forged bind result could cause problems well beyond the LDAP server itself.
Red Hat scores it 9.0 CRITICAL (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). The attack works over the network and needs no privileges or user interaction. Attack complexity is rated high because the attacker must be on-path. Scope is changed, and the impact to confidentiality, integrity and availability is high.
Exploitation status: The CISA Known Exploited Vulnerabilities (KEV) catalog has no entry for this CVE, so KEV does not confirm active exploitation.
What's Vulnerable
Red Hat lists the 389-ds-base package (including module streams) as affected in:
- Red Hat Directory Server 11 (
389-ds-base,redhat-ds:11/389-ds-base) - Red Hat Directory Server 12 (
389-ds-base,redhat-ds:12/389-ds-base) - Red Hat Directory Server 13
- Red Hat Enterprise Linux 8 (
389-ds-base,389-ds:1.4/389-ds-base) - Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux 10
Status is unknown for Red Hat Enterprise Linux 6 and 7.
Patch Status
The NVD record does not include fixed package versions or a patch release. The CVE is not in KEV, so CISA has set no required action or due date. If you run an affected 389-ds-base or Red Hat Directory Server deployment, check the Red Hat CVE page and the Bugzilla entry below for updates and fixed packages.