Red Hat released fixes for CVE-2026-18922, a critical (CVSS 9.8) authentication-bypass vulnerability in 389 Directory Server. An unauthenticated attacker able to connect over LDAPS can submit a failed SASL PLAIN bind using cn=Directory Manager, then perform a SASL ANONYMOUS bind on the same connection; Cyrus SASL can retain the prior identity, granting Directory Manager privileges with full confidentiality, integrity, and availability impact.
The updates also remediate CVE-2026-18355, a SASL wrapped-record heap buffer overflow; CVE-2026-18453, a pre-authentication NULL-pointer denial of service; and CVE-2026-76560, which lets anonymous LDAP clients bypass certain SELFDN ACI bind-rule checks using an empty bind DN. Red Hat issued advisories for affected 389 Directory Server and Red Hat Directory Server packages across supported RHEL 6, 8, 9, and 10 streams; administrators should promptly apply the relevant 389-ds-base or redhat-ds updates. No known public exploits were reported in the referenced advisories.

See affected versions and whether adversaries are exploiting it.
25 events from the most recent confirmed update back to the earliest known activity.
Oracle Linux published ELSA-2026-647910 for Oracle Linux 8 389 Directory Server packages, including 389-ds-base and related development, library, SNMP, and python3-lib389 packages. The update remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560.
Rocky Linux published RLSA-2026:64791 for Rocky Linux 8, updating 389-ds-base and related packages. The advisory remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560, and includes lib389 replication-handling fixes.
Rocky Linux published RLSA-2026:64784 for Rocky Linux 9, updating 389-ds-base and related packages. The advisory remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-76560, and CVE-2026-78701, and includes lib389 replication fixes.
Rocky Linux published RLSA-2026:64785 for Rocky Linux 10, updating 389-ds-base and related packages. The advisory remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-76560, and CVE-2026-78701, along with lib389 replication fixes.
AlmaLinux published security advisory ALSA-2026:64785 for AlmaLinux 10, updating 389-ds-base and related packages. The update remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-76560, and CVE-2026-78701; the source reported no known exploits.
AlmaLinux published ALSA-2026:64784 for AlmaLinux 9 repositories, updating 389-ds-base and related development, library, SNMP, and python3-lib389 packages. The update remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-76560, and CVE-2026-78701.
Amazon Linux published advisory ALAS-2026-3909 for Amazon Linux 2, updating 389 Directory Server packages affected by CVE-2026-18922. The critical network-reachable flaw has a CVSS v3.0 score of 9.8; the referenced security check reported no known exploits.
Oracle Linux published ELSA-2026-64785-0 for Oracle Linux 10, updating 389 Directory Server packages including 389-ds-base and python3-lib389. The update remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-76560, and CVE-2026-78701.
Oracle Linux published ELSA-2026-64784-0 for Oracle Linux 9, updating 389 Directory Server packages including 389-ds-base, development and library packages, SNMP support, and python3-lib389. The update remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-76560, and CVE-2026-78701.
Red Hat issued critical advisory RHSA-2026:64778 for 389-ds-base in RHEL 9.2 update channels, supplying version 2.2.4-22.el9_2. The update remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560, and includes a lib389 replication total-initialization fix.
Red Hat issued critical advisory RHSA-2026:64781 for 389-ds-base in RHEL 9.4 Update Services for SAP Solutions and associated lifecycle channels. The 2.4.5-29.el9_4 update remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560, and includes replication-initialization fixes.
Red Hat issued critical advisory RHSA-2026:64783 for 389-ds-base in RHEL 9.6 EUS and associated update channels. The 2.6.1-24.el9_6 update fixes CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560, along with lib389 replication fixes.
Red Hat issued Critical advisory RHSA-2026:64804 for 389-ds-base on RHEL 10.0 Extended Update Support and associated CodeReady Linux Builder channels. The update supplies 389-ds-base 3.0.6-21.el10_0 and remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560.
Red Hat issued critical advisory RHSA-2026:64789 for the 389-ds:1.4 module in RHEL 8.4 AUS and Extended Life Cycle Long Life channels. The update provides 389-ds-base 1.4.3.34-7.module+el8.4.0+24797+f0b70e95 and remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560, along with a lib389 replication initialization fix.
Red Hat issued critical advisory RHSA-2026:64776 for the 389-ds:1.4 module on RHEL 8.8 SAP Solutions, Telecommunications Update Service, and Extended Life Cycle Long Life channels. The update provides 389-ds-base 1.4.3.35-21.module+el8.8.0+24788+bed99f90 and remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560.
Red Hat issued critical advisory RHSA-2026:64779 for the redhat-ds:12 module in Red Hat Directory Server 12.2 E4S on RHEL 9.2. The update provides 389-ds-base 2.2.7-18 and remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-19843, and CVE-2026-76560, as well as a replication total-initialization issue.
Red Hat issued critical advisory RHSA-2026:64791 for the 389-ds:1.4 module on RHEL 8, including RHEL 8.10 Extended Life Cycle Support. The update provides 389-ds-base 1.4.3.39-28 and fixes CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560.
Red Hat issued critical advisory RHSA-2026:64771 for 389-ds-base on RHEL 7 Extended Life Cycle Support. The update provides version 1.3.11.1-15.el7_9 for x86_64, s390x, ppc64, and ppc64le, remediating CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560, plus a replication total-initialization issue.
Red Hat issued critical advisory RHSA-2026:64780 for the redhat-ds:12 module on RHEL 9, updating Red Hat Directory Server 12.4 E4S. The update fixes CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-19843, and CVE-2026-76560, and addresses a lib389 replication-initialization issue.
Red Hat issued critical advisory RHSA-2026:64793 for the redhat-ds:11 module on RHEL 8, updating Red Hat Directory Server 11.9 packages. The update remediates five flaws in 389-ds-base, including CVE-2026-19843 command injection alongside CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, and CVE-2026-76560.
Red Hat issued critical advisory RHSA-2026:64792 for the redhat-ds:11 module, updating Red Hat Directory Server 11.7 E4S on RHEL 8.8. The update provides 389-ds-base 1.4.3.34-18.module+el8dsrv+24812+0acb1821 and remediates CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-19843, and CVE-2026-76560, along with lib389 replication fixes.
Red Hat published RHSA security updates for supported RHEL and Red Hat Directory Server streams, including RHSA-2026:64784 for RHEL 9, RHSA-2026:64785 for RHEL 10, RHSA-2026:64790 for RHEL 8.6 AUS/EUS, and RHSA-2026:64811 for RHEL 6. The updates remediate CVE-2026-18922 and, in applicable package streams, CVE-2026-18355, CVE-2026-18453, CVE-2026-76560, and connection-stall flaw CVE-2026-78701; administrators were advised to update affected packages.
Multiple 389 Directory Server vulnerabilities were published, including CVE-2026-18355 (SASL wrapped-record heap overflow), CVE-2026-18453 (pre-authentication NULL-pointer denial of service), CVE-2026-18922 (SASL PLAIN authentication bypass), and CVE-2026-76560 (SELFDN ACI bypass). CVE-2026-18922 can allow an unauthenticated LDAPS client to obtain Directory Manager privileges by following a failed SASL PLAIN bind with an anonymous bind on the same connection.
Red Hat documented a connection-stall issue associated with an incomplete sasl_io_recv() fix for padded SASL UNBIND messages. Because a partial receive does not advance the buffered-data offset, a remote SASL-authenticated client can leave connections stalled until I/O timeout, potentially causing resource exhaustion through repeated connections; Red Hat addressed it in RHEL 9 and 10 advisories RHSA-2026:64784 and RHSA-2026:64785.
Red Hat documented CVE-2026-19843 as a command injection in cockpit-389-ds, where LDAP distinguished names are concatenated into shell commands executed through a root-privileged Cockpit channel. A user able to create or rename directory entries can plant a crafted DN that executes commands as root when a privileged operator views the entry or its ACIs; Red Hat issued fixes across affected Directory Server releases for RHEL 8, 9, and 10.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
37 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.