CVE-2026-76560: Incorrect Authorization in Red Hat Red Hat Directory Server 11
CVE-2026-76560 is a high-severity vulnerability in Red Hat Directory Server 11 (389 Directory Server) where the SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value. This flaw allows an unauthenticated client to bypass access control checks intended for authenticated users, potentially enabling unauthorized modification or addition of directory entries. The vulnerability affects deployments that define ACIs using userattr="attribute#SELFDN" or userattr="attribute#USERDN" bind rules on attributes that can hold empty values. Red Hat Directory Server does not ship such ACIs by default, so the real-world impact depends on specific deployment configurations. No official fix or patch is currently available. Mitigations include reviewing and adjusting ACIs to prevent empty attribute values or restricting anonymous binds, or disabling anonymous access entirely.
AI Analysis
Technical Summary
The vulnerability arises from the SELFDN ACI bind-rule evaluator in 389 Directory Server (Red Hat Directory Server 11) incorrectly treating an anonymous LDAP client's empty bind DN as matching an empty stored attribute value. This allows an unauthenticated client to satisfy access control checks that require a matching authenticated identity, enabling unauthorized operations such as adding or modifying directory entries. The flaw specifically affects deployments with ACIs using userattr="attribute#SELFDN" or userattr="attribute#USERDN" bind rules on attributes permitted to hold empty values. Red Hat Directory Server does not include such ACIs by default, so exploitation depends on deployment specifics. The CVSS 3.1 base score is 7.5 (high severity) with network attack vector, low complexity, no privileges required, no user interaction, unchanged scope, no confidentiality impact, high integrity impact, and no availability impact. No known exploits are reported in the wild. No patch or official fix is currently available, and mitigation involves configuration review and restricting anonymous access.
Potential Impact
An unauthenticated attacker can bypass intended access control restrictions by exploiting the incorrect matching of empty bind DN values, allowing unauthorized modification or addition of directory entries that should be restricted to specific authenticated users. There is no confidentiality or availability impact demonstrated. The severity depends on whether the vulnerable ACI configuration is present in the deployment, as Red Hat Directory Server does not ship such ACIs by default.
Mitigation Recommendations
Until an official fix is available, administrators should review all ACIs using userattr="...#SELFDN" bind rules and ensure the target attribute cannot be set to an empty value. Alternatively, add explicit authmethod restrictions to prevent anonymous binds from satisfying the check. Disabling anonymous access to the directory entirely removes the attack surface. Monitor Red Hat's advisory for updates on patch availability.
CVE-2026-76560: Incorrect Authorization in Red Hat Red Hat Directory Server 11
Description
CVE-2026-76560 is a high-severity vulnerability in Red Hat Directory Server 11 (389 Directory Server) where the SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value. This flaw allows an unauthenticated client to bypass access control checks intended for authenticated users, potentially enabling unauthorized modification or addition of directory entries. The vulnerability affects deployments that define ACIs using userattr="attribute#SELFDN" or userattr="attribute#USERDN" bind rules on attributes that can hold empty values. Red Hat Directory Server does not ship such ACIs by default, so the real-world impact depends on specific deployment configurations. No official fix or patch is currently available. Mitigations include reviewing and adjusting ACIs to prevent empty attribute values or restricting anonymous binds, or disabling anonymous access entirely.
CVSS v3.1
Score 7.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from the SELFDN ACI bind-rule evaluator in 389 Directory Server (Red Hat Directory Server 11) incorrectly treating an anonymous LDAP client's empty bind DN as matching an empty stored attribute value. This allows an unauthenticated client to satisfy access control checks that require a matching authenticated identity, enabling unauthorized operations such as adding or modifying directory entries. The flaw specifically affects deployments with ACIs using userattr="attribute#SELFDN" or userattr="attribute#USERDN" bind rules on attributes permitted to hold empty values. Red Hat Directory Server does not include such ACIs by default, so exploitation depends on deployment specifics. The CVSS 3.1 base score is 7.5 (high severity) with network attack vector, low complexity, no privileges required, no user interaction, unchanged scope, no confidentiality impact, high integrity impact, and no availability impact. No known exploits are reported in the wild. No patch or official fix is currently available, and mitigation involves configuration review and restricting anonymous access.
Potential Impact
An unauthenticated attacker can bypass intended access control restrictions by exploiting the incorrect matching of empty bind DN values, allowing unauthorized modification or addition of directory entries that should be restricted to specific authenticated users. There is no confidentiality or availability impact demonstrated. The severity depends on whether the vulnerable ACI configuration is present in the deployment, as Red Hat Directory Server does not ship such ACIs by default.
Mitigation Recommendations
Until an official fix is available, administrators should review all ACIs using userattr="...#SELFDN" bind rules and ensure the target attribute cannot be set to an empty value. Alternatively, add explicit authmethod restrictions to prevent anonymous binds from satisfying the check. Disabling anonymous access to the directory entirely removes the attack surface. Monitor Red Hat's advisory for updates on patch availability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-19T13:01:16.163Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Gcve Source
- db.gcve.eu
Threat ID: 6a9ee180acd9273b49e681b5
Added to database: 09/07/2026, 16:08:32 UTC
Last enriched: 09/07/2026, 16:09:58 UTC
Last updated: 09/08/2026, 02:37:44 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.