Skip to main content

CWE archive

CWE-90 CVEs

Programmatic archive

74 CVEs tagged with CWE-9010 Critical, 27 High, 31 Medium, 6 Low, 0 Unrated.

CVE-2026-11770

Published Jul 31, 2026

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Becau…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-58222

Published Jul 30, 2026

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare reque…

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-44617

Published Jul 30, 2026

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escapi…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-44616

Published Jul 30, 2026

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attack…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-4256

Published Jul 9, 2026

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects Pa…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13696

Published Jul 7, 2026

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. This issue affects Liman MYS:…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57288

Published Jun 24, 2026

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-11748

Published Jun 22, 2026

A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LD…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49268

Published Jun 17, 2026

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42568

Published Jun 10, 2026

Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search f…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-45559

Published Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds th…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-46745

Published May 25, 2026

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authenticatio…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-44930

Published May 22, 2026

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-44063

Published May 21, 2026

An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDAP queries and obtain limited information or modify LDAP ent…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41919

Published May 19, 2026

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44671

Published May 14, 2026

ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-44304

Published May 12, 2026

Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Pyt…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-33609

Published Apr 22, 2026

Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40606

Published Apr 21, 2026

mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmproxy 12.…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40459

Published Apr 17, 2026

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting i…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-40193

Published Apr 16, 2026

maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolat…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-0636

Published Apr 15, 2026

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This…

CVSS 5.5 · Medium
evidence mentions
15
Buzz score
40.7

CVE-2026-39962

Published Apr 9, 2026

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDA…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-34578

Published Apr 9, 2026

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 74 CVEsPage 1 of 3