CVE-2026-11790

Public on 2026-06-09
Modified on 2026-06-12
Description
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core 389-ds-base Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H