CVE-2026-86345
CVE-2026-86345 is a critical-severity vulnerability with a CVSS 3.x base score of 9.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-923.
Key facts
- Severity: Critical (CVSS 3.x base score 9.0)
- EPSS exploit prediction: 0% (30th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-923
- Published:
- Last modified:
Description
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Frequently asked questions
- What is CVE-2026-86345?
- A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
- How severe is CVE-2026-86345?
- CVE-2026-86345 has a CVSS 3.x base score of 9.0, rated critical severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-86345 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (30th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-86345?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-86345 published?
- CVE-2026-86345 was published on 2026-10-02.
References
- https://access.redhat.com/security/cve/CVE-2026-86345
- https://bugzilla.redhat.com/show_bug.cgi?id=2529332
Other CWE-923 vulnerabilities
- CVE-2019-17440 — Critical (CVSS 10.0): Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation…
- CVE-2024-41889 — Critical (CVSS 9.8): Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited,…
- CVE-2026-34205 — Critical (CVSS 9.6): Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps…
- CVE-2026-92173 — Critical (CVSS 9.1): Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent…
- CVE-2023-28078 — Critical (CVSS 9.1): Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A…
- CVE-2026-92172 — High (CVSS 8.8): Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent…