PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73644 OpenIdentityPlatform CVE debrief

PatchSiren debrief for CVE-2026-73644: OpenDJ SASL PLAIN authorization identity path vulnerability allows an authenticated account with PROXIED_AUTH privilege to assume unauthorized identities. This issue is fixed in OpenDJ version 5.1.2. Defenders should prioritize patching and monitor authentication events to prevent potential privilege escalation and lateral movement. The vulnerability affects OpenDJ deployments, particularly those with complex authorization setups. Security teams should review and update OpenDJ to version 5.1.2 or later, restrict access to sensitive identities and permissions, and monitor authentication and authorization events for potential abuse.

Vendor
OpenIdentityPlatform
Product
OpenDJ
CVSS
CRITICAL 9.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-18
Advisory published
2026-08-13
Advisory updated
2026-09-18

Who should care

LDAP administrators, OpenDJ users, security teams responsible for authentication and authorization, and operators managing affected systems should prioritize patching and review their authorization setups to prevent potential privilege escalation and lateral movement. Those responsible for monitoring authentication and authorization events should be aware of the potential for abuse and take steps to detect and respond to it. Additionally, security teams, 3

Why it matters

The OpenDJ SASL PLAIN authorization identity path vulnerability allows an authenticated account to assume unauthorized identities, potentially leading to privilege escalation and lateral movement. Defenders should prioritize patching to version 5.1.2 or later and monitor authentication events.

  • Potential unauthorized identity assumption
  • Increased risk of privilege escalation
  • Need for urgent patching or mitigation
  • Potential for lateral movement

Technical summary

The OpenDJ SASL PLAIN authorization identity path vulnerability allows an authenticated account with the PROXIED_AUTH privilege to assume any resolvable non-root identity outside the identities permitted by its proxy ACI. This issue is fixed in OpenDJ version 5.1.2. The vulnerability affects OpenDJ deployments, particularly those with complex authorization setups. Defenders should prioritize patching to prevent potential privilege escalation and lateral movement. The fix returns INVALID_CREDENTIALS (49) before password verification when the target authorization identity is not permitted.

Defensive priority

High

Recommended defensive actions

  • Review and update OpenDJ to version 5.1.2 or later
  • Restrict access to sensitive identities and permissions
  • Monitor authentication and authorization events for potential abuse
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in OpenDJ's SASL PLAIN authorization identity path. The issue allows an authenticated account with the PROXIED_AUTH privilege to assume any resolvable non-root identity outside the identities permitted by its proxy ACI.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73644 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73644

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73644 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73644

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.