Sceawere

Vulnerability Detail

CVE-2026-86345UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

389-ds-base StartTLS Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9
Creation Date
23h ago
Vendor
Red Hat
Product
Red Hat Directory Server 11
Attack Type
Improper Restriction of Communication Channel to Intended Endpoints
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.0",
  "pubDate": "2026-10-02T00:17:04.180Z",
  "pubdate": "2026-10-02T00:17:04.180Z",
  "executiveSummary": "A critical vulnerability exists in 389-ds-base involving the improper handling of buffered plaintext data during the StartTLS negotiation process.\nThe flaw allows an on-path attacker to perform a protocol-level injection by inserting malicious LDAP messages into the server's input buffer before the TLS upgrade is finalized.\nThis vulnerability leads to messageID collision, enabling the attacker to intercept and replace legitimate server responses with fabricated data.\nThe primary security impact is the potential for authentication bypass, where a client application may incorrectly interpret a failed LDAP Bind operation as a successful authentication.\nThe attack requires an on-path position (e.g., Man-in-the-Middle) to intercept and inject packets prior to the establishment of the secure TLS tunnel.\nNo pre-existing authentication is required to initiate the attack; it relies on the server's failure to purge non-TLS buffered data after the StartTLS transition.",
  "technicalDetails": "The vulnerability originates from a failure in the 389-ds-base connection state machine during the StartTLS upgrade sequence. When a client initiates a StartTLS request over an existing plaintext LDAP connection, the server receives the request and processes the TLS handshake. However, the server implementation fails to discard or flush any plaintext bytes that were already read from the socket and buffered in the input queue prior to the completion of the TLS negotiation.\nAn on-path attacker can exploit this by injecting a crafted LDAP request into the TCP stream immediately following the StartTLS initiation sequence. Because the server maintains this leftover plaintext buffer, it reads the attacker's injected message as if it were part of the initial plaintext stream, or processes it immediately upon entering the secure state, depending on the internal buffer pointer management.\nThe exploitation flow is as follows: 1) The client sends a legitimate StartTLS request to the server. 2) The attacker intercepts the traffic and injects an unauthorized LDAP Bind request or other operation into the buffer before the server-side TLS handshake completes. 3) The server negotiates the TLS upgrade but fails to purge the pre-existing buffer. 4) The server processes the attacker's injected LDAP message within the new secure context. 5) By carefully timing the messageID, the attacker ensures their malicious request is processed by the server while the client is still expecting a response to a different, legitimate operation.\nThe result is a messageID collision where the server's response to the attacker's injected command is delivered to the client as the response to the client's legitimate request. This effectively desynchronizes the protocol state. In the context of an authentication sequence, if the attacker injects a Bind request that the server perceives as successful, the client receives this success notification, potentially granting the attacker unauthorized access or causing the client to behave as if authentication was established securely when it was actually manipulated.\nThis vulnerability resides in the core LDAP connection management logic of 389-ds-base. It is a logic flaw regarding stream integrity and buffer lifecycle management. Since the attack occurs at the network layer during the protocol transition, it requires no specific privileges on the directory server itself, provided the attacker can influence the transit path between the client and the LDAP server."
}
CVE-2026-86345: 389-ds-base StartTLS Injection Vulnerability (CRITICAL Severity, CVSS: 9.0) | Sceawere