THREAT OPS › Threat News › [NVD] CVE-2026-73644 (CRITICAL 9.6) — OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy
[NVD] CVE-2026-73644 (CRITICAL 9.6) — OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy
CVE-2026-73644 CVSS: 9.6 CRITICAL Published: 2026-08-13T18:18:20.093
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different
Indicators of compromise
- CVE-2026-73644cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73644