CVE-2026-103547

PUBLISHED
Published: 30 Sept 2026, 19:40
Last modified:30 Sept 2026, 19:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.2 CRITICAL
v4.0 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Sept 2026, 19:40
Published
Vulnerability first disclosed
30 Sept 2026, 19:55
Last Modified
Vulnerability information updated

Description

In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)

CVSS Metrics

  • v4.0•CRITICAL•Score: 9.2CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Techniques & Countermeasures

  • CWE-863•Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Affected Systems

  • openbsd•openbsd

    ≥ 7.8, < errata 057 | ≥ 7.9, < errata 021

References (4)