{"id":"GHSA-p279-2cqp-84jg","summary":"OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check","details":"### Summary\nWhen a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a **different** user, PlainSASLMechanismHandler verified only the PROXIED_AUTH privilege and never evaluated the \"proxy\" access-control right (the mayProxy ACI scope check). As a result, any account holding the proxied-auth privilege could assume **any resolvable non-root identity** without being granted a proxy ACI for that target.\n\nThis diverges from every other proxy path in OpenDJ — the proxied-authorization controls (RFC 4370) and the DIGEST-MD5 / GSSAPI authzid handlers all require **both** the privilege **and** the mayProxy scope grant.\n\n### Impact\nPrivilege escalation / authorization bypass: a holder of proxied-auth can act as arbitrary directory users beyond the scope intended by the deployment's proxy ACIs, defeating the ACI-based restriction on *which* identities may be impersonated. Root/Directory Manager is not assumable this way.\n\n### Fix\nEnforce the mayProxy scope check on the SASL PLAIN authzid path (both dn: and u:/bare forms), sharing one hasProxyAccess helper with the DIGEST-MD5/GSSAPI path. Denial returns INVALID_CREDENTIALS (49) **before** password verification — matching DIGEST-MD5/GSSAPI — so an unauthenticated client cannot distinguish a missing privilege from a missing ACI grant.\n\n### Workaround\nRestrict or revoke the proxied-auth privilege until upgraded.","aliases":["CVE-2026-73644"],"modified":"2026-08-13T18:10:56.305354Z","published":"2026-07-24T21:46:39Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-24T21:46:39Z","nvd_published_at":null,"cwe_ids":["CWE-285","CWE-639"]},"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenDJ/security/advisories/GHSA-p279-2cqp-84jg"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenDJ/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed"},{"type":"PACKAGE","url":"https://github.com/OpenIdentityPlatform/OpenDJ"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenDJ/releases/tag/5.1.2"}],"affected":[{"package":{"name":"org.openidentityplatform.opendj:opendj-server-legacy","ecosystem":"Maven","purl":"pkg:maven/org.openidentityplatform.opendj/opendj-server-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.2"}]}],"versions":["4.10.0","4.10.1","4.10.2","4.4.10","4.4.11","4.4.12","4.4.13","4.4.14","4.4.15","4.4.7","4.4.8","4.4.9","4.5.0","4.5.1","4.5.2","4.5.3","4.5.4","4.5.5","4.5.6","4.5.7","4.5.8","4.5.9","4.6.1","4.6.2","4.6.3","4.6.4","4.6.5","4.7.0","4.8.0","4.8.1","4.8.2","4.9.0","4.9.1","4.9.2","4.9.3","4.9.4","5.0.1","5.0.2","5.0.3","5.0.4","5.1.0","5.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-p279-2cqp-84jg/GHSA-p279-2cqp-84jg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}