CVE-2026-14969
published 2026-07-07CVE-2026-14969: A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations…
PriorityP420medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.08%
0.2th percentile
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 389-ds_1.4 | 389-ds-base | — | — |
| port389 | 389-ds-base | — | — |
| redhat-ds_11 | 389-ds-base | — | — |
| redhat-ds_12 | 389-ds-base | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged file
ghsa_unreviewed·2026-07-07
CVE-2026-14969 [MEDIUM] CWE-329 A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged file
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.
Red Hat
389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption
vendor_redhat·2026-07-07·CVSS 4.4
CVE-2026-14969 [MEDIUM] CWE-329 389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption
389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.
Statement: The 389-ds-base attribute encryption feature uses a static initialization vector for AES-CBC and 3DES-CBC operations, making the encryption deterministic. This does not enable direct plaintext recovery but allows ciphertext comparison across entries sharing the same attribute value.
Exploiting this requires privileged read access to the raw database files on disk, which on Red Hat Enterpr
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-14969 389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption [fedora-all]
bugzilla·2026-07-07·CVSS 4.4
CVE-2026-14969 [MEDIUM] CVE-2026-14969 389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption [fedora-all]
CVE-2026-14969 389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw was found in 389-ds-base. The LDBM backend attribute encryption implementation in ldap/servers/slapd/back-ldbm/ldbm_attrcrypt.c uses a hardcoded static initialization vector (IV) — 16 bytes of 0x61 — for all AES-CBC-PAD and 3DES-CBC-PAD encryption operations. CBC mode requires a unique, unpredictable IV per encryption operation to provide semantic security. The static IV causes identical plaintext attribute values to produce identical ciph
Bugzilla
CVE-2026-14969 389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption
bugzilla·2026-07-07·CVSS 4.4
CVE-2026-14969 [MEDIUM] CVE-2026-14969 389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption
CVE-2026-14969 389-ds-base: 389-ds-base: Static initialization vector in AES-CBC/3DES-CBC attribute encryption
A flaw was found in 389-ds-base. The LDBM backend attribute encryption implementation in ldap/servers/slapd/back-ldbm/ldbm_attrcrypt.c uses a hardcoded static initialization vector (IV) — 16 bytes of 0x61 — for all AES-CBC-PAD and 3DES-CBC-PAD encryption operations. CBC mode requires a unique, unpredictable IV per encryption operation to provide semantic security. The static IV causes identical plaintext attribute values to produce identical ciphertext, enabling an attacker with privileged read access to the LDBM database files to detect plaintext equality across entries by comparing ciphertext blocks and to facilitate offline cryptanalysis of encrypted attributes.
2026-07-07
Published