CVE-2026-44930

Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository

Title source: cna
STIX 2.1

Description

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

References (1)

Core 1
Core References

Scores

EPSS 0.0002
EPSS Percentile 4.3%

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-90
Status published
Products (3)
Apache Software Foundation/Apache CXF < 3.6.11
Apache Software Foundation/Apache CXF 4.0.0 - 4.1.6
Apache Software Foundation/Apache CXF 4.2.0 - 4.2.1
Published May 22, 2026
Tracked Since May 22, 2026