SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14969

MEDIUM · CVSS 4.4 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

A vulnerability exists in the 389-ds-base due to the use of a hardcoded static initialization vector for AES-CBC and 3DES-CBC encryption in the LDBM backend, which can allow attackers with privileged filesystem access to infer plaintext equality between encrypted entries by analyzing ciphertext blocks. This could lead to potential data exposure risks. Organizations using 389-ds-base should prioritize addressing this issue to safeguard sensitive information against unauthorized access.

CVE
CVE-2026-14969
Severity
MEDIUM
CVSS
4.4
EPSS
0.08%

Original NVD Description

A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)