Get real-time updates on Telegram
CVE-2026-86345: Red Hat Directory Server 11 (exact versions not specified); +7 more affected products
CVE-2026-86345. CVSS 3.1 base score 9.0 (CRITICAL, Vendor/CNA). EPSS 0.00382 (percentile 0.29992), scored 2026-10-06.
Affected technology
Red Hat Directory Server 11 · Exact affected versions not specified by the source
Red Hat
Red Hat Directory Server 12 · Exact affected versions not specified by the source
Red Hat
Red Hat Directory Server 13 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 10 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 6 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 7 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 8 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 9 · Exact affected versions not specified by the source
Red Hat
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source says the server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. Vendor/CNA’s CVSS 3.1 assessment (base score 9.0/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-923
- CCR priority
- 36.1 /100 (P4)
- CVSS 3.1
- 9.0 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H · Vendor/CNA
- EPSS
- 0.00382 · percentile 0.29992 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-86345.html