CVE-2020-26168

CRITICAL

Hazelcast IMDG Enterprise 4.0-4.0.2 and Jet Enterprise 4.0-4.2 - LDAP Authentication Bypass

Title source: llm
STIX 2.1

Description

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.

Scores

CVSS v3 9.8
EPSS 0.0158
EPSS Percentile 72.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
hazelcast/hazelcast 4.0 - 4.0.3
hazelcast/jet 4.0 - 4.2
Published Nov 09, 2020
Tracked Since Feb 18, 2026