CVE-2026-19404
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-19404, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat 389_directory_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in 389 Directory Server where two replication-maintenance operations, CleanAllRUV and Abort CleanAllRUV, lack proper authorization checks. This allows unauthenticated remote attackers or low-privilege authenticated users to invoke these operations, potentially removing replica IDs, purging changelog records, and disrupting cleanup tasks. This can leave replication inconsistent or unavailable.

Detection Guidance

Check 389 Directory Server logs for unauthorized CleanAllRUV or Abort CleanAllRUV extended operation requests. Monitor replication metadata changes or changelog purges. Use LDAP search commands to verify if these operations are being invoked without proper authorization.

Impact Analysis

The impact includes replication inconsistencies or unavailability, which can disrupt directory services. Unauthorized removal of replica IDs or purging of changelogs may cause data loss or corruption. The vulnerability can be exploited remotely without authentication if default settings are used, increasing the risk of service disruption.

Compliance Impact

This vulnerability could lead to unauthorized data access or deletion, violating integrity and availability requirements in GDPR and HIPAA. Inconsistent or unavailable replication may result in non-compliance with data integrity and security controls mandated by these regulations.

Mitigation Strategies

Set nsslapd-allow-anonymous-access to rootdse or off to block unauthenticated clients. Restrict replication LDAP ports to trusted networks. Apply vendor patches or upgrade to supported versions where fixes are available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19404. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart