CVE-2026-11770Disclosure(redhat / 389_directory_server)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for redhat 389_directory_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 389_directory_server
  • directory_server
  • enterprise_linux

Threat summary

  • Exploit tooling references are present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
389_directory_serverdirectory_serverenterprise_linux

8 versions affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-31: 1Exploit Tool / Code · 2026-07-31: 1Technical Details · 2026-07-31: 107-31
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨HIGH - 389 Directory Server CleanAllRUV ExtOp LDAP Filter Injection Info Leak (CVE-2026-11770) 389 Directory Server’s CleanAllRUV replication status-check extended operation allows unauthenticated injection of LDAP search filters. The extop performs a privileged search against cn=config and returns a boolean match, enabling probing/extraction of sensitive config metadata (e.g., replication bind DNs, password storage scheme info). 👉Affected: 389-ds-base (versions TBD)

    Post summary

    The post discloses CVE‑2026‑11770, an LDAP filter injection vulnerability in 389 Directory Server that allows unauthenticated extraction of sensitive configuration data.

    0000088
    275 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSredhat389_directory_server---
Appredhatdirectory_server11.0--
Appredhatdirectory_server12.0--
Appredhatdirectory_server13.0--
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more