CVE-2026-86345 — Red Hat
CRITICALCVE-2026-86345 is a critical-severity (CVSS 9) CWE-923 vulnerability. No vendor fix is recorded yet; mitigation options are listed below.
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject…
Description
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2026-86345 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This flaw is rated Moderate rather than Critical or Important, despite a CVSS base score of 9.0. Exploitation requires an attacker to hold an active on-path (man-in-the-middle) position on the network segment between an LDAP client and the server at the moment StartTLS is negotiated -- a materially harder precondition…
Disable StartTLS on port 389 and require ldaps:// (port 636) instead, which has no cleartext prefix to inject into. No configuration-only mitigation fully closes the issue on port 389 while StartTLS remains enabled.Source: Red Hat security advisory for CVE-2026-86345 (CC BY 4.0)
Frequently Asked Questions
Is CVE-2026-86345 in your dependencies?
Find it across , including transitive dependencies.