389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result
Published Oct 1, 2026
9.0
CRITICALCVSS 3.1
Description
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Directory Server 11 | affected |
| |||
| Red Hat | Red Hat Directory Server 12 | affected |
| |||
| Red Hat | Red Hat Directory Server 13 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
No data.
No data.
Red Hat Directory Server 11
389-ds-base
Affected
Red Hat Directory Server 11
redhat-ds:11/389-ds-base
Affected
Red Hat Directory Server 12
389-ds-base
Affected
Red Hat Directory Server 12
redhat-ds:12/389-ds-base
Affected
Red Hat Directory Server 13
389-ds-base
Affected
Red Hat Enterprise Linux 10
389-ds-base
Affected
Red Hat Enterprise Linux 6
389-ds-base
Out of support scope
Red Hat Enterprise Linux 7
389-ds-base
Out of support scope
Red Hat Enterprise Linux 8
389-ds-base
Affected
Red Hat Enterprise Linux 8
389-ds:1.4/389-ds-base
Affected
Red Hat Enterprise Linux 9
389-ds-base
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Directory Server 11 | 389-ds-base | Affected | n/a |
| Red Hat Directory Server 11 | redhat-ds:11/389-ds-base | Affected | n/a |
| Red Hat Directory Server 12 | 389-ds-base | Affected | n/a |
| Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Affected | n/a |
| Red Hat Directory Server 13 | 389-ds-base | Affected | n/a |
| Red Hat Enterprise Linux 10 | 389-ds-base | Affected | n/a |
| Red Hat Enterprise Linux 6 | 389-ds-base | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | 389-ds-base | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | 389-ds-base | Affected | n/a |
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Affected | n/a |
| Red Hat Enterprise Linux 9 | 389-ds-base | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Disable StartTLS on port 389 and require ldaps:// (port 636) instead, which has no cleartext prefix to inject into. No configuration-only mitigation fully closes the issue on port 389 while StartTLS remains enabled.
Red Hat statement
This flaw is rated Moderate rather than Critical or Important, despite a CVSS base score of 9.0. Exploitation requires an attacker to hold an active on-path (man-in-the-middle) position on the network segment between an LDAP client and the server at the moment StartTLS is negotiated -- a materially harder precondition than a purely remote, unauthenticated attack, and one that rules out the ease-of-exploitation bar Critical requires. The outcome is also not arbitrary code execution: exploitation causes a client-side application (e.g. a PAM module) to incorrectly treat a failed authentication attempt as successful, granting access through that application's own, legitimate, pre-existing login mechanism rather than through execution of attacker-supplied code. 389-ds-base itself is not compromised by this flaw -- the server suffers no privilege escalation and no data exfiltration beyond what an anonymous bind could already obtain; the security impact is entirely realized in separate, downstream client applications that trust the LDAP bind result.
Red Hat mitigation
Disable StartTLS on port 389 and require ldaps:// (port 636) instead, which has no cleartext prefix to inject into. No configuration-only mitigation fully closes the issue on port 389 while StartTLS remains enabled.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (4)
- https://access.redhat.com/security/cve/CVE-2026-86345 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2529332 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-86345
- https://www.cve.org/CVERecord?id=CVE-2026-86345
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-86345 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2529332 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-86345 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-86345 |
Change history (0)
No recorded changes yet.