Authorization Bypass Through User-Controlled Key Affecting org.openidentityplatform.opendj:opendj-server-legacy package, versions [,5.1.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGOPENIDENTITYPLATFORMOPENDJ-18313059
  • published26 Jul 2026
  • disclosed24 Jul 2026
  • credithypnguyen1209

Introduced: 24 Jul 2026

New CVE NOT AVAILABLE CWE-285  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade org.openidentityplatform.opendj:opendj-server-legacy to version 5.1.2 or higher.

Overview

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the SASL PLAIN authentication process. An attacker can gain unauthorized access to arbitrary directory user accounts by supplying an authorization identity (authzid) that resolves to a different user, provided they possess the proxied-auth privilege but lack the required proxy ACI scope grant. This allows impersonation of any resolvable non-root identity beyond intended access controls.

Workaround

This vulnerability can be mitigated by restricting or revoking the proxied-auth privilege until the issue is resolved.

CVSS Base Scores

version 4.0
version 3.1