CVE-2026-86345: Schwachstellen-Eintrag (NVD)
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-18 | 2026-10-01 |
|---|---|---|
| ≥90 % | 0 | 377 |
| ≥50 % | 0 | 1137 |
| ≥10 % | 0 | 2 |
| <10 % | 300 | 451 |
CVE-2026-86345 | Red Hat Directory Server/Enterprise Linux 389-ds-base cleartext transmission (EUVD-2026-91139)
A vulnerability identified as problematic has been detected in Red Hat Directory Server and Enterprise Linux. This vulnerability affects unknown code of the component 389-ds-base. This manipulation causes cleartext transmission of sensitive
Noch keine Analyse zu CVE-2026-86345
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.