LDAP injection in 389-ds-base - CVE-2026-11770
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive server configuration metadata.
The vulnerability exists due to ldap injection in the CleanAllRUV replication status-check extended operation when processing crafted LDAP search filters. A remote attacker can inject LDAP search filters to disclose sensitive server configuration metadata.
The search is performed against cn=config with elevated replication plugin privileges and returns a boolean match result, which can expose replication bind DNs and password storage scheme information.