What is CVE-2026-18651?
A vulnerability was found in 389 Directory Server where during SASL PLAIN authentication, it installs connection-level bind credentials before checking if the account is locked. If the account is locked, the bind fails for the client, but the already-installed credentials could temporarily allow authentication. Affected servers should be patched.
Azərbaycanca: 389 Directory Server-də SASL PLAIN autentifikasiyası zamanı boşluq aşkarlanıb. Server hesab bağlama yoxlamasından əvvəl bağlantı səviyyəsində etimadnamələri quraşdırır, bu isə bağlanmış hesabla müvəqqəti autentifikasiyaya imkan verə bilər. Təsirlənən serverlərdə yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which authentication mechanism in 389 Directory Server is affected by CVE-2026-18651?
This vulnerability occurs during SASL PLAIN authentication.
How does CVE-2026-18651 in 389 Directory Server enable authentication with a locked account?
The server installs connection-level bind credentials before checking if the account is locked, which could temporarily allow authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.