External risk intelligence

389-ds-base StartTLS Injection Allows Bind Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-86345

The vulnerability affects 389-ds-base, a directory server component. While LDAP services are often internal, they are sometimes exposed or reachable in deployments requiring external directory lookups or cross-network identity services. Public internet exposure is not the default or standard deployment pattern for directory servers, but they are more reachable than purely local-only components.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability identified in 389-ds-base, a component used in directory services. The flaw could allow an attacker to trick systems into believing a failed login was successful, potentially impacting authentication processes. The primary concern at this stage is to confirm if this specific technology is deployed within our environment.

  • Flaw allows fake successful logins.
  • Affects directory services authentication.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker positioned between the client and the 389 Directory Server can intercept the connection. By manipulating the data exchanged during the StartTLS negotiation, the attacker can trick the server into processing a malicious LDAP message. This message exploits a vulnerability related to message IDs, causing the server to send back a fraudulent response, making a failed login appear successful to the client.

  • Attacker must be on the network path.
  • Crafted LDAP message during TLS negotiation.
  • Client accepts successful authentication.

Live Threat

Current exploitation, exposure, and threat context

A flaw in 389-ds-base could allow an attacker on the network to interfere with StartTLS connections. This could trick a client application into believing an authentication attempt was successful when it actually failed, by injecting a crafted LDAP message that causes a message ID collision.

  • Directory server authentication data at risk.
  • Attackers inject messages during TLS negotiation.
  • Failed authentications may appear successful.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical vulnerability in 389-ds-base necessitates action from teams managing identity and access, likely including infrastructure, platform, and security operations. The immediate priority is to identify all instances of the affected software, determine their exposure and business criticality, and assign ownership for remediation. A risk-based approach to planning updates or applying mitigations is essential.

  • Identify affected directory services.
  • Verify external reachability and criticality.
  • Plan and coordinate remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is 389-ds-base?

389-ds-base is an enterprise-grade directory server used to manage identity information, user accounts, and authentication data. It functions as a centralized database that applications query to verify credentials or retrieve profile details. Organizations typically rely on it to provide consistent access management across their internal networks and integrated services.

What does CVE-2026-86345 mean in plain English?

This vulnerability is classified as CWE-923, which relates to improper restriction of communication channel properties. In this specific case, the server fails to clear pending data when upgrading a connection to StartTLS. This weakness allows an attacker to inject fraudulent instructions that the server might process as if they came from the legitimate user, potentially tricking the system into accepting an incorrect password as a valid one.

How does an attacker trigger this 389-ds-base flaw?

An attacker must be positioned as an on-path entity between the client and the server to intercept the connection. They must send a crafted LDAP message during the specific window when the connection is upgrading to TLS. Simply communicating with the server after a secure connection is already established does not trigger the vulnerability, nor does sending standard traffic before the StartTLS request begins.

Is my network at risk according to Halo Surface Signal?

Halo Surface Signal indicates this is a possible risk because, while directory servers are typically internal, they are sometimes reachable across networks for identity services. If your 389-ds-base instances are reachable from untrusted network segments or external environments rather than being restricted to strictly private, local-only segments, the likelihood of an attacker successfully positioning themselves to intercept traffic increases.

What should I do if I run 389-ds-base?

Your first step is to perform an inventory of all systems running 389-ds-base to determine which services are active. Once identified, evaluate the network accessibility of these instances to see if they are reachable from non-essential segments. Prioritize verifying authentication flows and coordinate with your infrastructure team to monitor official channels for security updates or recommended configuration mitigations.

References