Apache · Apache Apisix · CVE-2026-75020
**Name of the Vulnerable Software and Affected Versions**
Apache APISIX versions 2.11.0 through 3.17.0
**Description**
An LDAP Injection occurs due to improper neutralization of special elements used in an LDAP query. This allows a caller with valid credentials for one LDAP directory entry to authenticate through APISIX as a consumer mapped to a different entry, bypassing the restrictions intended by the plugin's configured scope.
**Recommendations**
Upgrade to version 3.18.0.