CWE-90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

73 vulnerabilities with CWE-90
CVE-2026-58222 HIGH
Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes
CVSS 8.8
CVE-2026-44617 ANALYSIS PENDING
Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
CVE-2026-44616 ANALYSIS PENDING
Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
CVE-2026-47303 HIGH
Microsoft .NET 10.0 - ASP.NET Core Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-4256 HIGH
LDAP Injection in PEAKUP's PassGate
CVSS 8.2
CVE-2026-13696 HIGH
LDAP Injection in HAVELSAN's Liman MYS
CVSS 8.8
CVE-2026-57288 LOW
Jenkins Active Directory Plugin < 2.41.1 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVSS 3.7
CVE-2026-11748 MEDIUM
Central Dogma < 0.84.0 - Unauthenticated LDAP Injection via SearchFirstActiveDirectoryRealm
CVE-2026-49268 CRITICAL
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
CVSS 9.1
CVE-2026-42568 MEDIUM
YAMCS yamcs-core 5.12.7 - LDAP Injection
CVSS 4.3
CVE-2026-45559 MEDIUM
Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only)
CVSS 4.9
CVE-2026-46745 MEDIUM
Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token
CVSS 5.3
CVE-2026-44930 CRITICAL
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
CVSS 9.8
CVE-2026-44063 MEDIUM
Netatalk 2.1.0-4.4.2 and >=4.5.0 - Authenticated LDAP Injection via Crafted Filter Input
CVSS 4.2
CVE-2026-41919 CRITICAL
Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
CVSS 9.1
CVE-2026-44671 HIGH
ZITADEL: LDAP Filter Injection in Login Flow
CVSS 7.5
CVE-2026-44304 HIGH
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
CVSS 8.1
CVE-2026-33609 MEDIUM
LDAP DN injection
CVSS 5.3
CVE-2026-40606 MEDIUM
ProxyAuth Addon LDAP Injection in mitmproxy
CVSS 4.8
CVE-2026-40459 HIGH
LDAP Injection in PAC4J
CVSS 8.8
CVE-2026-40193 HIGH
Maddy Mail Server: LDAP Filter Injection via Unsanitized Username
CVSS 8.2
CVE-2026-0636 MEDIUM
LDAP Injection Vulnerability in LDAPStoreHelper.java
CVSS 6.5
CVE-2026-39962 CRITICAL
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
CVSS 9.6
CVE-2026-34578 HIGH
OPNsense <26.1.6 WebGUI Login Username - LDAP Injection
CVSS 8.2
CVE-2026-29138 HIGH
SEPPmail Secure Email Gateway - PGP Decryption Sender LDAP Injection
CVSS 7.5
Details
Vulnerabilities 73