PatchSiren cyber security CVE debrief
CVE-2026-73644 OpenIdentityPlatform CVE debrief
PatchSiren debrief for CVE-2026-73644: OpenDJ SASL PLAIN authorization identity path vulnerability allows an authenticated account with PROXIED_AUTH privilege to assume unauthorized identities. This issue is fixed in OpenDJ version 5.1.2. Defenders should prioritize patching and monitor authentication events to prevent potential privilege escalation and lateral movement. The vulnerability affects OpenDJ deployments, particularly those with complex authorization setups. Security teams should review and update OpenDJ to version 5.1.2 or later, restrict access to sensitive identities and permissions, and monitor authentication and authorization events for potential abuse.
- Vendor
- OpenIdentityPlatform
- Product
- OpenDJ
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-18
Who should care
LDAP administrators, OpenDJ users, security teams responsible for authentication and authorization, and operators managing affected systems should prioritize patching and review their authorization setups to prevent potential privilege escalation and lateral movement. Those responsible for monitoring authentication and authorization events should be aware of the potential for abuse and take steps to detect and respond to it. Additionally, security teams, 3
Why it matters
The OpenDJ SASL PLAIN authorization identity path vulnerability allows an authenticated account to assume unauthorized identities, potentially leading to privilege escalation and lateral movement. Defenders should prioritize patching to version 5.1.2 or later and monitor authentication events.
- Potential unauthorized identity assumption
- Increased risk of privilege escalation
- Need for urgent patching or mitigation
- Potential for lateral movement
Technical summary
The OpenDJ SASL PLAIN authorization identity path vulnerability allows an authenticated account with the PROXIED_AUTH privilege to assume any resolvable non-root identity outside the identities permitted by its proxy ACI. This issue is fixed in OpenDJ version 5.1.2. The vulnerability affects OpenDJ deployments, particularly those with complex authorization setups. Defenders should prioritize patching to prevent potential privilege escalation and lateral movement. The fix returns INVALID_CREDENTIALS (49) before password verification when the target authorization identity is not permitted.
Defensive priority
High
Recommended defensive actions
- Review and update OpenDJ to version 5.1.2 or later
- Restrict access to sensitive identities and permissions
- Monitor authentication and authorization events for potential abuse
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in OpenDJ's SASL PLAIN authorization identity path. The issue allows an authenticated account with the PROXIED_AUTH privilege to assume any resolvable non-root identity outside the identities permitted by its proxy ACI.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73644 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73644
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73644 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73644
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenIdentityPlatform/OpenDJ/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenIdentityPlatform/OpenDJ/releases/tag/5.1.2
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenIdentityPlatform/OpenDJ/security/advisories/GHSA-p279-2cqp-84jg
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.