Skip to main content
QUIETLYTIC
Vulnerability

Authen::SASL::Perl Authentication Bypass (CVE-2026-86219)

CVE-2026-86219 is a CVSS 9.8 critical authentication bypass in the Perl Authen::SASL::Perl::DIGEST_MD5 module, letting a captured response be replayed to authenticate as another user.

CVE-2026-86219
Threat Level
CRITICAL
CVSS
9.8
Status
Monitored
Confidence
Medium
Affected Products
Authen::SASL::Perl (CPAN)

CVE-2026-86219 is a critical (CVSS 3.1 base 9.8) authentication-bypass vulnerability in Authen::SASL::Perl::DIGEST_MD5, versions before 2.2100, a CPAN module implementing SASL DIGEST-MD5 authentication for Perl applications.

What the vulnerability does

Per NVD’s description, the module’s server_start function generates a fresh nonce and sends it in the authentication challenge, but nothing in server_step later verifies that the client’s response actually carries that nonce back. Because server_step derives its expected digest purely from the client-supplied parameters, any response verifies as long as its digest matches the nonce it itself carries — the server never confirms that nonce was the one it actually issued. A per-session replay counter is similarly keyed on the client-supplied nonce and starts empty each session, so a captured first exchange (nc=00000001) passes that check too.

The practical exploit: an attacker who observes one successful qop=auth SASL exchange for a given service, host, realm, and user can replay that captured response in a later session and authenticate as that user — without ever knowing their password.

The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw needing no authentication or user interaction, with full confidentiality, integrity, and availability impact — consistent with a complete authentication bypass.

Fix and affected versions

Fixed in Authen::SASL::Perl::DIGEST_MD5 2.2100 and later, per NVD’s reference to the module’s changelog and the upstream GitHub patch commit.

What we don’t yet have

This record traces to NVD and the module’s own upstream repository/changelog references — no independent second-source corroboration or CISA KEV listing is present, so confidence is medium.

Why this matters

Any application relying on this module for SASL DIGEST-MD5 authentication — commonly used to authenticate against LDAP, IMAP, or SMTP services from Perl — should treat one observed successful login exchange as effectively a captured, reusable credential until upgraded, since the nonce-replay protection SASL is specifically designed to provide is not actually enforced.

Frequently Asked Questions

What is CVE-2026-86219? A CVSS 9.8 critical authentication-bypass vulnerability in the Perl Authen::SASL::Perl::DIGEST_MD5 module, allowing a captured authentication exchange to be replayed to log in as the same user without a password.

Which version fixes CVE-2026-86219? Authen::SASL::Perl::DIGEST_MD5 2.2100 and later.

Is CVE-2026-86219 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)

Related intelligence


Analyst tools