← All Advisories

389 Directory Server SELFDN Access Control Logic Matches an Empty Anonymous Bind DN Against Empty Stored Attributes, Bypassing ACI Restrictions

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-76560

Key Details

CVECVE-2026-76560
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is none.
Affected productssee table below
Classified asCWE-863 (Incorrect Authorization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
Red HatRed Hat Directory Server 11
Red HatRed Hat Directory Server 12
Red HatRed Hat Directory Server 11.5 E4S for RHEL 8
Red HatRed Hat Directory Server 11.7 E4S for RHEL 8
Red HatRed Hat Directory Server 11.9 for RHEL 8
Red HatRed Hat Directory Server 12.2 E4S for RHEL 9
Red HatRed Hat Directory Server 12.4 E4S for RHEL 9
Red HatRed Hat Directory Server 13.2
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-76560
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-76560