A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-11770 exploits a critical input validation flaw in 389 Directory Server's CleanAllRUV replication operation. An unauthenticated attacker can inject malicious LDAP search filter syntax into the extended operation handler, which then executes queries against the cn=config directory with elevated replication plugin privileges. This allows attackers to extract sensitive metadata including replication bind DNs, password hashing schemes, and other server configuration details without authentication. Organizations running 389 Directory Server in replication scenarios face immediate risk, as the vulnerability requires no credentials and can be exploited remotely over standard LDAP ports.
Casky's security skills—powered by Claude AI's extended reasoning capabilities—map this vulnerability to MITRE ATT&CK technique T1059 (Command and Scripting Interpreter), detecting it as LDAP injection abuse for command execution and data exfiltration. When analyzing network traffic or application logs, practitioners would see findings flagging: unauthenticated LDAP requests with syntactically malformed or suspicious filter parameters targeting replication operations, boolean-based blind injection patterns in CleanAllRUV requests, and queries executed with unexpected privilege escalation. The skills would correlate these indicators with CWE-90 (Improper Neutralization of Special Elements used in an LDAP Query) to identify attempts to break out of intended query contexts. Security teams can then use these findings to hunt for exploitation attempts, validate patching status, and implement access controls restricting LDAP replication operations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-11770. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation