CVE-2026-4256

HIGH

LDAP Injection in PEAKUP's PassGate

Title source: cna
STIX 2.1

Description

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0021
EPSS Percentile 11.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-90
Status published
Products (1)
PEAKUP Technology Inc./PassGate < 30042026
Published Jul 09, 2026
Tracked Since Jul 09, 2026