PatchSiren cyber security CVE debrief
CVE-2026-76560 Red Hat CVE debrief
A flaw in 389 Directory Server allows an unauthenticated client to bypass access control checks intended for authenticated users due to incorrect matching of empty bind DNs. This CVE has a CVSS score of 7.5 and is considered HIGH severity. The vulnerability arises from the SELFDN ACI bind-rule evaluator incorrectly handling empty bind DNs, potentially leading to unauthorized directory modifications. Defenders should assess their exposure, prioritize patching, and review access control configurations.
- Vendor
- Red Hat
- Product
- Red Hat Directory Server 11
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for 389 Directory Server instances, especially those exposed to untrusted LDAP clients, should assess their exposure and prioritize patching and configuration reviews.
Why it matters
This CVE allows unauthenticated clients to bypass access controls in 389 Directory Server, potentially leading to unauthorized directory modifications. Defenders should prioritize patching and reviewing access control configurations.
- Potential unauthorized directory modifications
- Bypass of intended access controls
- Increased risk of data tampering or unauthorized changes
Technical summary
The SELFDN ACI bind-rule evaluator in 389 Directory Server incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value. This allows an unauthenticated client to perform operations restricted to a specific authenticated user, potentially leading to unauthorized directory modifications or data tampering. The vulnerability can be mitigated by verifying and patching affected systems, reviewing access control configurations, and monitoring LDAP client activity for potential abuse.
Defensive priority
Defenders should prioritize verifying and patching 389 Directory Server instances, especially those exposed to untrusted LDAP clients.
Recommended defensive actions
- Verify and apply patches for 389 Directory Server
- Review and update access control configurations for SELFDN ACI
- Monitor LDAP client activity for potential abuse
- Perform a thorough review of directory server configurations to ensure SELFDN ACI is properly implemented
- Conduct vulnerability scanning to identify potentially exposed systems
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide details on the flaw, but additional information on affected versions and remediation steps is limited. Further verification is needed to determine the full scope of affected systems and to confirm the efficacy of proposed mitigations. Defenders should verify patch application and review SELFDN ACI configurations for potential vulnerabilities.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76560 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76560
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76560 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76560
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-76560
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.