MAVEN · JULY 2026 · EARLY WARNING

OpenDJ SASL PLAIN Authentication Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-P279-2CQP-84JGSeverity: HIGH

An early warning has been issued regarding a potential vulnerability in the OpenDJ SASL PLAIN authentication mechanism. This vulnerability reportedly allows users with proxied-auth privilege to assume any resolvable non-root identity without proper authorization, potentially leading to privilege escalation and authorization bypass.

What happened

The vulnerability, tracked as GHSA-P279-2CQP-84JG, appears to affect the OpenDJ SASL PLAIN authentication mechanism. Specifically, it is under investigation whether users with proxied-auth privilege can bypass the proxy ACI scope check, allowing them to assume any resolvable non-root identity without proper authorization. This could lead to unauthorized privilege escalation and bypass of authorization controls.

To assess your exposure, review your use of OpenDJ and determine if you are utilizing the SASL PLAIN authentication mechanism with proxied-auth privileges. If so, it is recommended to upgrade to a version where the mayProxy scope check is enforced on the SASL PLAIN authzid path. Consult the primary sources for more detailed information and guidance on mitigation steps.

For the latest updates and detailed technical information, refer to the GitHub Advisory Database entry [GHSA-p279-2cqp-84jg](https://github.com/advisories/GHSA-p279-2cqp-84jg). This incident is still under investigation, and further details may emerge as the analysis progresses.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If opendj-server-legacy is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats