Critical Flaw in 389-ds-base Could Lead to Authentication Bypass (CVE-2026-86345)
A vulnerability (CVE-2026-86345) has been identified in 389-ds-base, where the server fails to discard plaintext bytes during StartTLS negotiation. This could allow an on-path attacker to inject a crafted LDAP message, potentially leading to a client application treating a failed authentication attempt as successful.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai