A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.Referenceshttps://access.redhat.com/security/cve/CVE-2026-11785https://bugzilla.redhat.com/show_bug.cgi?id=2485427https://redhat.atlassian.net/browse/PSIRTSUPT-7600