THREAT OPS › Threat News › [NVD] CVE-2026-18651 (MEDIUM 5.4) — A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the alr
[NVD] CVE-2026-18651 (MEDIUM 5.4) — A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the alr
CVE-2026-18651 CVSS: 5.4 MEDIUM Published: 2026-08-03T16:16:29.073
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-18651cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18651