---
cve: "CVE-2026-86219"
severity: "LOW"
cvss: 3.1
epss: "2.8%"
vendor: "Microsoft"
kev: false
exploited: false
published: "2026-09-06 18:17:23"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T00:49:23+02:00"
---

# CVE-2026-86219

> 3.1 LOW

## Beschreibung

Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step.

server_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client returns. server_step derives the expected digest from the client's own parameters, so a response verifies whenever its digest matches the nonce it carries. The count table it also checks is keyed on the client-supplied nonce and starts empty in each new server object, so a captured first response, carrying `nc=00000001`, passes that too. RFC 2831 defines the nonce in the response as the value the server sent in the preceding challenge.

An attacker who observes one successful `qop=auth` exchange can replay the captured response against a later session for the same service, host, realm and user, and authenticate as that user without knowing the password.

## Referenzen

- <https://datatracker.ietf.org/doc/html/rfc2831#section-2.1.2>
- <https://github.com/perl-authen-sasl/perl-authen-sasl/commit/94337367030612842924f697cead29964a96448d.patch>
- <https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L203-222>
- <https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L410-414>
- <https://metacpan.org/release/EHUELS/Authen-SASL-2.2100/changes>
- <https://www.cve.org/CVERecord?id=CVE-2025-40918>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-86219) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
