CVE-2026-18922 is an improper-authentication flaw in 389 Directory Server's SASL PLAIN bind handling. A Cyrus SASL auxiliary property can retain an identity from a failed SASL PLAIN bind. If an unrelated SASL bind subsequently succeeds on the same connection, 389 Directory Server can install the stale identity as the connection's authenticated identity. An attacker can induce a failed bind using the Directory Manager identity and then successfully bind anonymously, or as a valid low-privileged user, to receive Directory Manager authority without valid Directory Manager credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical CVSS 9.8 authentication-bypass and privilege-escalation vulnerability in Red Hat's 389 Directory Server. A failed SASL PLAIN bind using cn=Directory Manager can leave a stale Cyrus SASL identity that is inherited by a subsequent SASL ANONYMOUS bind on the same LDAPS connection, allowing an unauthenticated remote attacker to obtain Directory Manager privileges.
A critical 389-ds-base privilege-escalation flaw in which SASL PLAIN authentication can obtain Directory Manager privileges because of a stale identity in a Cyrus SASL auxiliary property.
A critical privilege-escalation vulnerability in 389-ds-base where SASL PLAIN authentication can leverage a stale Cyrus SASL auxiliary-property identity to become Directory Manager.
A critical privilege-escalation vulnerability in 389-ds-base: SASL PLAIN authentication can elevate access to Directory Manager because of a stale identity in a Cyrus SASL auxiliary property. The advisory assigns the displayed CVSS 3.0 score/vector to this CVE.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.