CVE-2026-18651 Details
Description
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.
A vulnerability exists in 389 Directory Server during SASL PLAIN authentication. The server applies connection-level bind credentials before checking if the account is locked. If an account is found to be locked after the credentials are applied, the server informs the client of the failure but does not remove the authenticated state from the connection. This allows a client to use valid credentials for a locked account to access resources and privileges associated with that account, undermining the purpose of account locking as a means of access control.
To address this vulnerability, it is recommended to rotate the LDAP password of an account when it is locked, as simply locking the account is insufficient. This vulnerability is present in Red Hat Directory Server versions 11, 12, 13, and in Red Hat Enterprise Linux 7 and 8.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-18651 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2510617 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat directory server | 11.0 12.0 13.0 |
CPE
Remediation
| |
| redhat 389 directory server | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 9, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |