CVE-2026-86219 is a critical (CVSS 3.1 base 9.8) authentication-bypass vulnerability in Authen::SASL::Perl::DIGEST_MD5, versions before 2.2100, a CPAN module implementing SASL DIGEST-MD5 authentication for Perl applications.
What the vulnerability does
Per NVD’s description, the module’s server_start function generates a fresh nonce and sends it in the authentication challenge, but nothing in server_step later verifies that the client’s response actually carries that nonce back. Because server_step derives its expected digest purely from the client-supplied parameters, any response verifies as long as its digest matches the nonce it itself carries — the server never confirms that nonce was the one it actually issued. A per-session replay counter is similarly keyed on the client-supplied nonce and starts empty each session, so a captured first exchange (nc=00000001) passes that check too.
The practical exploit: an attacker who observes one successful qop=auth SASL exchange for a given service, host, realm, and user can replay that captured response in a later session and authenticate as that user — without ever knowing their password.
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw needing no authentication or user interaction, with full confidentiality, integrity, and availability impact — consistent with a complete authentication bypass.
Fix and affected versions
Fixed in Authen::SASL::Perl::DIGEST_MD5 2.2100 and later, per NVD’s reference to the module’s changelog and the upstream GitHub patch commit.
What we don’t yet have
This record traces to NVD and the module’s own upstream repository/changelog references — no independent second-source corroboration or CISA KEV listing is present, so confidence is medium.
Why this matters
Any application relying on this module for SASL DIGEST-MD5 authentication — commonly used to authenticate against LDAP, IMAP, or SMTP services from Perl — should treat one observed successful login exchange as effectively a captured, reusable credential until upgraded, since the nonce-replay protection SASL is specifically designed to provide is not actually enforced.
Frequently Asked Questions
What is CVE-2026-86219?
A CVSS 9.8 critical authentication-bypass vulnerability in the Perl Authen::SASL::Perl::DIGEST_MD5 module, allowing a captured authentication exchange to be replayed to log in as the same user without a password.
Which version fixes CVE-2026-86219?
Authen::SASL::Perl::DIGEST_MD5 2.2100 and later.
Is CVE-2026-86219 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.