THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73644 (CRITICAL 9.6) — OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy

[NVD] CVE-2026-73644 (CRITICAL 9.6) — OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy

lownvdPublished 2026-08-13

CVE-2026-73644 CVSS: 9.6 CRITICAL Published: 2026-08-13T18:18:20.093

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73644