CVE-2026-86345
published 2026-10-02CVE-2026-86345: A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an…
PriorityP260critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
EPSS
0.38%
29.9th percentile
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 389-ds_1.4 | 389-ds-base | — | — |
| port389 | 389-ds-base | — | — |
| redhat-ds_11 | 389-ds-base | — | — |
| redhat-ds_12 | 389-ds-base | — | — |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result
vendor_redhat·2026-10-01·CVSS 9.0
CVE-2026-86345 [CRITICAL] CWE-923 389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result
389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Statement: This flaw is rated Moderate rather than Critical or Important, despite a CVSS base score of 9.0. Exploitation requires an attacker to hold an active on-path (man-in-the-midd
GHSA
A flaw was found in 389-ds-base.
ghsa_unreviewed·2026-10-02
CVE-2026-86345 [CRITICAL] CWE-923 A flaw was found in 389-ds-base.
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
VulDB
Red Hat Directory Server/Enterprise Linux 389-ds-base cleartext transmission (EUVD-2026-91139)
vuldb·2026-10-02·CVSS 9.0
CVE-2026-86345 [CRITICAL] Red Hat Directory Server/Enterprise Linux 389-ds-base cleartext transmission (EUVD-2026-91139)
A vulnerability identified as problematic has been detected in Red Hat Directory Server and Enterprise Linux. This vulnerability affects unknown code of the component 389-ds-base. This manipulation causes cleartext transmission of sensitive information.
This vulnerability is registered as CVE-2026-86345. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-86345 389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result [fedora-all]
bugzilla·2026-10-01·CVSS 9.0
CVE-2026-86345 [CRITICAL] CVE-2026-86345 389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result [fedora-all]
CVE-2026-86345 389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw was found in 389-ds-base. When a client negotiates StartTLS, the server (start_tls_io_enable() in start_tls_extop.c) replaces the connection's underlying socket with a TLS-wrapped one but does not discard or invalidate plaintext bytes already buffered from the socket (c_buffer_bytes/c_buffer_offset in connection.c), which are otherwise only reset on a BER parse error or after a fresh read -- neither of
Bugzilla
CVE-2026-86345 389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result
bugzilla·2026-09-07·CVSS 9.0
CVE-2026-86345 [CRITICAL] CVE-2026-86345 389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result
CVE-2026-86345 389-ds-base: 389-ds-base: StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result
A flaw was found in 389-ds-base. When a client negotiates StartTLS, the server (start_tls_io_enable() in start_tls_extop.c) replaces the connection's underlying socket with a TLS-wrapped one but does not discard or invalidate plaintext bytes already buffered from the socket (c_buffer_bytes/c_buffer_offset in connection.c), which are otherwise only reset on a BER parse error or after a fresh read -- neither of which occurs during the StartTLS transport switch. An on-path (man-in-the-middle) attacker can place a second LDAP message in the same TCP segment as the client's StartTLS request; after the server switches to TLS, it parses this smuggle
2026-10-02
Published