{"id":"AZL-94517","summary":"CVE-2026-18651 affecting package 389-ds-base 3.1.1-11","details":"A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.","modified":"2026-08-31T05:26:07Z","published":"2026-08-03T16:16:29Z","upstream":["CVE-2026-18651"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18651"}],"affected":[{"package":{"name":"389-ds-base","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/389-ds-base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.1.1-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94517.json"}}],"schema_version":"1.9.0"}