PT-2026-76566 · Hyperledger · Fabric-Ca

CVE-2026-53658

·

Published

2026-08-14

·

Updated

2026-09-04

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions fabric-ca (affected versions not specified)
Description When configured with an LDAP backend, the software fails to properly escape the username obtained from HTTP Basic authentication before including it in an LDAP uid search filter. This allows an unauthenticated attacker with network access to the CA enrollment endpoint to perform LDAP injection before password validation, potentially redirecting authentication attempts toward a victim account.
Recommendations Update to a fixed version if using an LDAP backend.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53658
GHSA-XGHW-P77P-3R7X
GO-2026-6234
OPENSUSE-SU-2026:21761-1

Affected Products

Fabric-Ca