PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76560 Red Hat CVE debrief

A flaw in 389 Directory Server allows an unauthenticated client to bypass access control checks intended for authenticated users due to incorrect matching of empty bind DNs. This CVE has a CVSS score of 7.5 and is considered HIGH severity. The vulnerability arises from the SELFDN ACI bind-rule evaluator incorrectly handling empty bind DNs, potentially leading to unauthorized directory modifications. Defenders should assess their exposure, prioritize patching, and review access control configurations.

Vendor
Red Hat
Product
Red Hat Directory Server 11
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

Defenders responsible for 389 Directory Server instances, especially those exposed to untrusted LDAP clients, should assess their exposure and prioritize patching and configuration reviews.

Why it matters

This CVE allows unauthenticated clients to bypass access controls in 389 Directory Server, potentially leading to unauthorized directory modifications. Defenders should prioritize patching and reviewing access control configurations.

  • Potential unauthorized directory modifications
  • Bypass of intended access controls
  • Increased risk of data tampering or unauthorized changes

Technical summary

The SELFDN ACI bind-rule evaluator in 389 Directory Server incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value. This allows an unauthenticated client to perform operations restricted to a specific authenticated user, potentially leading to unauthorized directory modifications or data tampering. The vulnerability can be mitigated by verifying and patching affected systems, reviewing access control configurations, and monitoring LDAP client activity for potential abuse.

Defensive priority

Defenders should prioritize verifying and patching 389 Directory Server instances, especially those exposed to untrusted LDAP clients.

Recommended defensive actions

  • Verify and apply patches for 389 Directory Server
  • Review and update access control configurations for SELFDN ACI
  • Monitor LDAP client activity for potential abuse
  • Perform a thorough review of directory server configurations to ensure SELFDN ACI is properly implemented
  • Conduct vulnerability scanning to identify potentially exposed systems
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the flaw, but additional information on affected versions and remediation steps is limited. Further verification is needed to determine the full scope of affected systems and to confirm the efficacy of proposed mitigations. Defenders should verify patch application and review SELFDN ACI configurations for potential vulnerabilities.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76560 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76560

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76560 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76560

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.