PT-2026-76566 · Hyperledger · Fabric-Ca
CVE-2026-53658
·
Published
2026-08-14
·
Updated
2026-09-04
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
fabric-ca (affected versions not specified)
Description
When configured with an LDAP backend, the software fails to properly escape the username obtained from HTTP Basic authentication before including it in an LDAP uid search filter. This allows an unauthenticated attacker with network access to the CA enrollment endpoint to perform LDAP injection before password validation, potentially redirecting authentication attempts toward a victim account.
Recommendations
Update to a fixed version if using an LDAP backend.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fabric-Ca