CVE-2026-18651Medium· 5.4▾ SunlitA flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is re…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.
directory_server = 11.0directory_server = 12.0directory_server = 13.0389_directory_serverenterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12112High· 7.8A flaw was found in the foreman-mcp-server
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-11788Medium· 5.9A flaw was found in 389 Directory Server
CVE-2026-15722High· 7.5A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base)
CVE-2026-18215Medium· 6.8Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant)
CVE-2026-46579High· 7.4A flaw was found in the OpenShift Router