What is CVE-2026-19404?
CVE-2026-19404 is a vulnerability in 389 Directory Server where the 'CleanAllRUV' and 'Abort CleanAllRUV' replication operations lack authorization checks. This allows an unauthenticated remote attacker to invoke them when 'nsslapd-allow-anonymous-access' is enabled (by default), potentially disrupting the service. It is recommended to disable this configuration.
Azərbaycanca: CVE-2026-19404 389 Directory Server-da "CleanAllRUV" və "Abort CleanAllRUV" replikasiya əməliyyatlarında avtorizasiya yoxlanışının olmaması zəifliyidir. Defolt olaraq aktiv olan "nsslapd-allow-anonymous-access" parametri ilə, autentifikasiya olunmamış uzaqdan hücumçu bu funksiyaları işə salaraq xidməti poza bilər. Bu konfiqurasiyanı deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
How to protect against CVE-2026-19404?
To protect against this vulnerability, it is recommended to disable the 'nsslapd-allow-anonymous-access' configuration.
What does CVE-2026-19404 allow a remote attacker to do?
This vulnerability may allow an unauthenticated remote attacker to invoke the 'CleanAllRUV' and 'Abort CleanAllRUV' replication operations, potentially disrupting the service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.