{"id":"CVE-2026-73644","summary":"OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant","details":"OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different user. Both dn: and u: or bare authzid forms could therefore let an authenticated account holding PROXIED_AUTH assume any resolvable non-root identity outside the identities permitted by its proxy ACI. The fix returns INVALID_CREDENTIALS (49) before password verification when the target authorization identity is not permitted. This issue is fixed in version 5.1.2.","aliases":["GHSA-p279-2cqp-84jg"],"modified":"2026-08-15T16:52:34.036006Z","published":"2026-08-13T17:52:48.641Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-285","CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73644.json"},"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenDJ/releases/tag/5.1.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73644.json"},{"type":"ADVISORY","url":"https://github.com/OpenIdentityPlatform/OpenDJ/security/advisories/GHSA-p279-2cqp-84jg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73644"},{"type":"FIX","url":"https://github.com/OpenIdentityPlatform/OpenDJ/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openidentityplatform/opendj","events":[{"introduced":"0"},{"fixed":"5c326850f1ab945cfca7ac9c5aaf77d1052c6bed"},{"fixed":"0802aa4081e1c175c40bde1af59439a20fcc5670"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.1.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["5.1.1","5.1.0","5.0.4","5.0.3","5.0.2","5.0.1","4.10.2","4.10.1","4.10.0","4.9.4","4.9.3","4.9.2","4.9.1","4.9.0","4.8.2","4.8.1","4.8.0","4.7.0","4.6.5","4.6.4","4.6.3","4.6.2","4.6.1","4.5.9","4.5.6","4.5.5","4.5.4","4.5.3","4.5.1","4.5.0","4.4.15","4.4.14","4.4.13","4.4.12","4.4.11","4.4.10","4.4.9","4.4.8","4.4.7","4.4.6","4.4.5","4.4.4","4.4.3","4.4.2","4.4.1","4.3.5","4.3.4","4.3.3","4.3.2","4.3.1","4.2.5","4.2.4","4.2.3","4.2.2","4.2.1","4.1.10","4.1.9","4.1.6","4.0.3","4.0.2","4.0.1","4.0.0-M1","3.0.0-M7","3.0.0-M6","3.0.0-M5","3.0.0-M4","last-common-commit-with-opendj-sdk-repo"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73644.json","vanir_signatures_modified":"2026-08-15T16:52:34Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"155686885625242155124211981484847536523","length":6304},"id":"CVE-2026-73644-4fed1596","signature_type":"Function","signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed","target":{"file":"opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java","function":"processSASLBind"}},{"deprecated":false,"digest":{"function_hash":"173381679740325442983922037869433708802","length":5172},"id":"CVE-2026-73644-6850cc28","signature_type":"Function","signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed","target":{"function":"setUp","file":"opendj-server-legacy/src/test/java/org/opends/server/types/PrivilegeTestCase.java"}},{"source":"https://github.com/openidentityplatform/opendj/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed","target":{"file":"opendj-server-legacy/src/test/java/org/opends/server/types/PrivilegeTestCase.java"},"deprecated":false,"digest":{"line_hashes":["208094423498710776790960373548461853981","334378739651239601157229849060843581802","162506016976480219042889773127785724858","38230255093373916204167309439354216216","21928578168045738368763385741657034988","75499557550498921325609470442980329681","325782482456683762236844834094526496471","300052161404602821806928081955707695410","86506634712429702097579545553141166060","157224439418595621934489674944852392852","88099160472244063891407073830208854626"],"threshold":0.9},"id":"CVE-2026-73644-7620d53a","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["263407092918383932971997127305604316876","187522937138233561564267555601871508580","221826373913272994047641585438677975477","82506381297581815044800328439798521710","323756492316312894460059213961452226743","48967191261016055042024735738611020713","160268021224510356212061132695017471117","277496218380704675969828663688029799885","107365362803413618540292079081282496282","51812878341884153474674671547250052496","182916124952575789017200876346636764282","88684506712394309861191228970577519394","23253198487364257116154832147697921499","192957417126765715406995851784915850748","179279954066802632058486442150791776213","335282786671777386441669663994439881245","118367859494719281311772965492551004695","319892909989994938184130715676254879520","62812157447429982701923355779824524429","195998007414567535269991471512404919171","258904148790068743419101432736528673640","326366965382059572616710276126213108253","58614108990469152437799514375321742328","261575039831612276078137229758201625103","15906682418430643250415475873070136416","33364378406098718168127937930651753967","329905872850570118099225880433799972523","104022062778227835961038567233282099625"]},"id":"CVE-2026-73644-78337230","signature_type":"Line","signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed","target":{"file":"opendj-server-legacy/src/main/java/org/opends/server/extensions/SASLContext.java"}},{"signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed","target":{"file":"opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java"},"deprecated":false,"digest":{"line_hashes":["150967654355352296141779144320274226052","181334928123492108333519679840062587830","293949540968280903538352693917672011553","108587633537507210242609878158511307392","216628819176825603862908918242355201886","294424110077403139566661082883691294812","181334928123492108333519679840062587830","293949540968280903538352693917672011553","108587633537507210242609878158511307392","212477331742559886133237943165922380306","210381069591144922767100173973833064766","327703116439325350409230592212524663774"],"threshold":0.9},"id":"CVE-2026-73644-d6bcf61e","signature_type":"Line"},{"id":"CVE-2026-73644-ea7ba646","signature_type":"Function","signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed","target":{"file":"opendj-server-legacy/src/main/java/org/opends/server/extensions/SASLContext.java","function":"hasPermission"},"deprecated":false,"digest":{"function_hash":"248321155339333876013971784048748117484","length":469}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}