Vulnerability record · CVE-2008-0926 · published 28 March 2008
CVE-2008-0926: Novell eDirectory eMBox SOAP interface authentication bypass
Novell · Edirectory
The SOAP interface to the eMBox module in Novell eDirectory relies on client-side authentication, so the server does not properly verify credentials on requests to /SOAP URIs. A remote, unauthenticated attacker can bypass authentication and then shut down the daemon or read arbitrary files. The flaw affects eDirectory 8.7.3.9 and earlier, 8.7.3.10, and 8.8.x before 8.8.2.
Description
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote access enabling file disclosure and daemon shutdown, with a high EPSS score despite no KEV listing.
What it is
The SOAP interface to the eMBox module in Novell eDirectory relies on client-side authentication, so the server does not properly verify credentials on requests to /SOAP URIs. A remote, unauthenticated attacker can bypass authentication and then shut down the daemon or read arbitrary files. The flaw affects eDirectory 8.7.3.9 and earlier, 8.7.3.10, and 8.8.x before 8.8.2.
Impact
An attacker gains unauthenticated access to eMBox SOAP functionality, allowing arbitrary file reads and a denial of service via daemon shutdown. This can expose sensitive directory data and take the directory service offline.
Attack surface
Reachable over the network through the eMBox SOAP interface by sending requests to /SOAP URIs; no authentication is required and no user interaction is indicated by the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is high at 0.58179 (99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade to eDirectory 8.8.2 or later, or apply the Novell/SUSE fix for the affected 8.7.3.x and 8.8.x builds
- Restrict network access to the eMBox SOAP interface (default TCP 8028) to trusted management hosts only
- Disable or stop the eMBox service if it is not required
- Place eDirectory management interfaces behind firewall rules and authenticated reverse proxies
- Monitor vendor advisories for updated builds covering 8.7.3.10
Detection
- Inspect eDirectory/HTTP logs for SOAP requests to /SOAP URIs, especially from unexpected source addresses
- Alert on eMBox daemon shutdown or restart events not tied to scheduled maintenance
- Monitor for anomalous file read activity or large data transfers from the eDirectory host
- Baseline normal eMBox management traffic and flag deviations in request volume or timing
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0926 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0926), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.