
🚨HIGH - 389 Directory Server CleanAllRUV ExtOp LDAP Filter Injection Info Leak (CVE-2026-11770) 389 Directory Server’s CleanAllRUV replication status-check extended operation allows unauthenticated injection of LDAP search filters. The extop performs a privileged search against cn=config and returns a boolean match, enabling probing/extraction of sensitive config metadata (e.g., replication bind DNs, password storage scheme info). 👉Affected: 389-ds-base (versions TBD)
Post summary
The post discloses CVE‑2026‑11770, an LDAP filter injection vulnerability in 389 Directory Server that allows unauthenticated extraction of sensitive configuration data.
