CVE-2026-49268
Published Jun 17, 2026A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated…
- evidence mentions
- 2
- Buzz score
- 21.0