GHSA-p279-2cqp-84jgCritical· 9.6▾ MidnightOpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a different user, PlainSASLMechanismHandler verified only the PROXIED_AUTH privilege and never evaluated the "proxy" access-control right (the mayProxy ACI scope check). As a result, any account holding the proxied-auth privilege could assume any resolvable non-root identity without being granted a proxy ACI for that target.
This diverges from every other proxy path in OpenDJ — the proxied-authorization controls (RFC 4370) and the DIGEST-MD5 / GSSAPI authzid handlers all require both the privilege and the mayProxy scope grant.
Privilege escalation / authorization bypass: a holder of proxied-auth can act as arbitrary directory users beyond the scope intended by the deployment's proxy ACIs, defeating the ACI-based restriction on which identities may be impersonated. Root/Directory Manager is not assumable this way.
Enforce the mayProxy scope check on the SASL PLAIN authzid path (both dn: and u:/bare forms), sharing one hasProxyAccess helper with the DIGEST-MD5/GSSAPI path. Denial returns INVALID_CREDENTIALS (49) before password verification — matching DIGEST-MD5/GSSAPI — so an unauthenticated client cannot distinguish a missing privilege from a missing ACI grant.
Restrict or revoke the proxied-auth privilege until upgraded.
org.openidentityplatform.opendj:opendj-server-legacy <= 5.1.1Upgrade to a patched release:
org.openidentityplatform.opendj:opendj-server-legacy 5.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73644Critical· 9.6OpenDJ is an LDAPv3 compliant directory service
GHSA-68r5-9hpg-7qw9Critical· 9.4OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
CVE-2026-48717Critical· 9.1Open Access Management (OpenAM) is an access management solution
CVE-2026-45048High· 8.5Open Access Management (OpenAM) is an access management solution
CVE-2026-45052Critical· 9.3Open Access Management (OpenAM) is an access management solution
CVE-2026-46498High· 7.6Open Access Management (OpenAM) is an access management solution