CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
64 vulnerabilities with CWE-90
CVE-2026-42568
MEDIUM
YAMCS yamcs-core 5.12.7 - LDAP Injection
CVSS 4.3
CVE-2026-45559
MEDIUM
Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only)
CVSS 4.9
CVE-2026-46745
MEDIUM
Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token
CVSS 5.3
CVE-2026-44930
CRITICAL
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
CVSS 9.8
CVE-2026-44063
MEDIUM
Netatalk 2.1.0-4.4.2 and >=4.5.0 - Authenticated LDAP Injection via Crafted Filter Input
CVSS 4.2
CVE-2026-41919
CRITICAL
Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
CVSS 9.1
CVE-2026-44671
HIGH
ZITADEL: LDAP Filter Injection in Login Flow
CVSS 7.5
CVE-2026-44304
HIGH
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
CVSS 8.1
CVE-2026-33609
MEDIUM
LDAP DN injection
CVSS 5.3
CVE-2026-40606
MEDIUM
ProxyAuth Addon LDAP Injection in mitmproxy
CVSS 4.8
CVE-2026-40459
HIGH
LDAP Injection in PAC4J
CVSS 8.8
CVE-2026-40193
HIGH
Maddy Mail Server: LDAP Filter Injection via Unsanitized Username
CVSS 8.2
CVE-2026-0636
MEDIUM
LDAP Injection Vulnerability in LDAPStoreHelper.java
CVE-2026-39962
CRITICAL
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
CVSS 9.6
CVE-2026-34578
HIGH
OPNsense <26.1.6 WebGUI Login Username - LDAP Injection
CVSS 8.2
CVE-2026-29138
HIGH
SEPPmail Secure Email Gateway - PGP Decryption Sender LDAP Injection
CVSS 7.5
CVE-2026-29131
HIGH
SEPPmail Secure Email Gateway - PGP Decryption Recipient LDAP Injection
CVSS 7.5
CVE-2026-27860
LOW
OX Dovecot Pro <3.1.0 - Auth Bypass
CVSS 3.7
CVE-2026-33751
MEDIUM
n8n Vulnerable to LDAP Filter Injection in LDAP Node
CVSS 4.8
CVE-2026-33289
HIGH
SuiterCRM has LDAP Filter Injection in Authentication Module
CVSS 8.8
CVE-2026-31828
HIGH
Parse Server <9.5.2-alpha.13/8.6.26 - LDAP Injection
CVSS 8.8
CVE-2026-25560
CRITICAL
WeKan < 8.19 - LDAP Injection in Authentication Filter
CVSS 9.8
CVE-2026-1498
HIGH
WatchGuard Fireware OS - Info Disclosure
CVE-2026-24130
MEDIUM
Moonraker < 0.10.0 - LDAP Injection via Login Endpoint
CVSS 5.3
CVE-2026-21880
MEDIUM
kanboard < 1.2.49 - LDAP Injection in Authentication Mechanism
CVSS 5.3
Details
Vulnerabilities
64