Upstream information

CVE-2026-76560 at MITRE

Description

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.

SUSE information

Overall state of this security issue: New

This issue is currently rated as having important severity.

CVSS v3 Scores
CVSS detail CNA (Red Hat)
Base Score 7.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact High
Availability Impact None
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 8
  • 389-ds-base >= 1.4.3.39-28.module+el8.10.0+24822+205d20dc
  • 389-ds-base-devel >= 1.4.3.39-28.module+el8.10.0+24822+205d20dc
  • 389-ds-base-legacy-tools >= 1.4.3.39-28.module+el8.10.0+24822+205d20dc
  • 389-ds-base-libs >= 1.4.3.39-28.module+el8.10.0+24822+205d20dc
  • 389-ds-base-snmp >= 1.4.3.39-28.module+el8.10.0+24822+205d20dc
  • python3-lib389 >= 1.4.3.39-28.module+el8.10.0+24822+205d20dc
Patchnames:
RHSA-2026:64791 (x86_64)


SUSE Timeline for this CVE

CVE page created: Tue Sep 8 16:53:56 2026
CVE page last modified: Tue Sep 8 16:53:56 2026