A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
https://access.redhat.com/errata/RHSA-2026:56050
https://access.redhat.com/errata/RHSA-2026:56048
https://access.redhat.com/errata/RHSA-2026:56047
https://access.redhat.com/errata/RHSA-2026:55794
https://access.redhat.com/errata/RHSA-2026:55758
https://access.redhat.com/errata/RHSA-2026:55757
https://access.redhat.com/errata/RHSA-2026:55756
https://access.redhat.com/errata/RHSA-2026:55532
https://access.redhat.com/errata/RHSA-2026:55530
https://access.redhat.com/errata/RHSA-2026:55426
https://access.redhat.com/errata/RHSA-2026:55425
https://access.redhat.com/errata/RHSA-2026:55424
https://access.redhat.com/errata/RHSA-2026:55423