CVE-2026-11785 — A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users — CVE Database · The Intelligence Room