← All Advisories

CVE-2026-18922

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-18922

Key Details

CVECVE-2026-18922
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-10-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-287 (Improper Authentication)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
Red HatRed Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
Red HatRed Hat Directory Server 12
Red HatRed Hat Directory Server 11.5 E4S for RHEL 8
Red HatRed Hat Directory Server 11.7 E4S for RHEL 8
Red HatRed Hat Directory Server 11.9 for RHEL 8
Red HatRed Hat Directory Server 12.2 E4S for RHEL 9
Red HatRed Hat Directory Server 12.4 E4S for RHEL 9
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-18922
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-18922