Skip to content
Red HatCVE-2026-18651

Red Hat 389 Directory Server: improper authentication

Medium5.4CVE-2026-18651 · Published Aug 3, 2026 · updated Aug 9, 2026

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Directory Server 11
Product
all versionsNo fix yet
Red Hat Directory Server 12
Product
all versionsNo fix yet
Red Hat Directory Server 13
Product
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-287

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: race condition
Medium4.4Aug 3
Red Hat GNU tar.: link following
Medium4.4Aug 3
Red Hat SSSD: out-of-bounds read
Medium5.5Aug 3
Red Hat GIMP: stack buffer overflow
Medium5.5Aug 3
Red Hat GIMP. A remote attacker: out-of-bounds write
Medium5.5Aug 3
Red Hat user creation: information disclosure
Medium6.6Aug 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.