Cyber & AI intelligence
Wasteland.
Briefs indexed2966
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-86345 2026-10-01

CVE-2026-86345: 389-ds-base StartTLS Injection Can Make a Failed LDAP Bind Look Successful

"A critical flaw in 389-ds-base (CVSS 9.0) lets an on-path attacker inject plaintext LDAP data during a StartTLS upgrade. This can make a client application treat a failed bind as a successful one."

A critical flaw in 389-ds-base (CVSS 9.0) lets an on-path attacker inject plaintext LDAP data during a StartTLS upgrade. This can make a client application treat a failed bind as a successful one.

What Is It

CVE-2026-86345 is a flaw in 389-ds-base, the LDAP server behind Red Hat Directory Server. When a client negotiates StartTLS, the server keeps any plaintext bytes it has already buffered from that connection instead of discarding them. An on-path attacker can use this to inject a crafted LDAP message, which the server processes after the TLS upgrade. The injected message's messageID collides with the client's own pending operation. As a result, the server sends the response to the injected message to the client in place of the response the client was waiting for.

Red Hat classifies the weakness as CWE-923. NVD lists the record's status as "Received".

Why It Matters

According to the description, the practical impact is authentication confusion: a client application can treat a failed bind attempt as successful. Directory servers often handle authentication for other systems, so a forged bind result could cause problems well beyond the LDAP server itself.

Red Hat scores it 9.0 CRITICAL (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). The attack works over the network and needs no privileges or user interaction. Attack complexity is rated high because the attacker must be on-path. Scope is changed, and the impact to confidentiality, integrity and availability is high.

Exploitation status: The CISA Known Exploited Vulnerabilities (KEV) catalog has no entry for this CVE, so KEV does not confirm active exploitation.

What's Vulnerable

Red Hat lists the 389-ds-base package (including module streams) as affected in:

Status is unknown for Red Hat Enterprise Linux 6 and 7.

Patch Status

The NVD record does not include fixed package versions or a patch release. The CVE is not in KEV, so CISA has set no required action or due date. If you run an affected 389-ds-base or Red Hat Directory Server deployment, check the Red Hat CVE page and the Bugzilla entry below for updates and fixed packages.

Sources