CVE-2026-86345
Received Received - Intake

StartTLS Plaintext Injection in 389 Directory Server

Vulnerability report for CVE-2026-86345, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: redhat-SADP

Description

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
red_hat 389-ds-base *
red_hat red_hat_enterprise_linux 8
red_hat openshift_container_platform 4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-923 The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the 389-ds-base LDAP server. During StartTLS negotiation, the server fails to clear buffered plaintext data from a client connection before switching to TLS. An on-path attacker can inject a crafted LDAP message into the same TCP segment as the client's StartTLS request. After TLS is established, the server processes this injected message, causing a messageID collision. The server then sends a forged response (e.g., a successful anonymous bind) to the client, making a failed authentication appear successful. This affects client applications like PAM/nss-pam-ldapd that rely on LDAP bind results.

Detection Guidance

To detect this vulnerability, monitor network traffic for StartTLS negotiation on port 389. Look for LDAP message injection attempts or messageID collisions during TLS handshakes. Use tools like Wireshark to capture and analyze LDAP traffic for anomalies in message sequences or unexpected responses after StartTLS negotiation.

Impact Analysis

This vulnerability can lead to unauthorized access in client applications that depend on LDAP authentication. An attacker can trick the client into accepting a failed login attempt as successful, potentially granting access through legitimate login mechanisms. This impacts applications using 389-ds-base with StartTLS on port 389, such as those in Red Hat Enterprise Linux or OpenShift environments.

Compliance Impact

This vulnerability could lead to unauthorized access, potentially violating compliance requirements for data protection and access control. GDPR requires strict access controls and breach notification, while HIPAA mandates secure authentication for protected health information. Exploitation may result in unauthorized data access, triggering non-compliance penalties or audit findings.

Mitigation Strategies
  • Disable StartTLS on port 389 and switch to using ldaps:// on port 636 for secure LDAP connections.
  • Update 389-ds-base to the latest patched version if available.
  • Restrict network access to port 389 to prevent on-path attacks.
  • Review client applications using LDAP bind results to ensure they handle authentication failures correctly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86345. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart