CVE-2026-44930
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
Title source: cnaDescription
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/c1zqxppo1m5z3kbdhjn5p991zk09ynkh
Scores
EPSS
0.0002
EPSS Percentile
4.3%
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-90
Status
published
Products (3)
Apache Software Foundation/Apache CXF
< 3.6.11
Apache Software Foundation/Apache CXF
4.0.0 - 4.1.6
Apache Software Foundation/Apache CXF
4.2.0 - 4.2.1
Published
May 22, 2026
Tracked Since
May 22, 2026