PT-2026-82450 · Apache · Apache Apisix

·

CVE-2026-75020

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache APISIX versions 2.11.0 through 3.17.0
Description An LDAP Injection occurs due to improper neutralization of special elements used in an LDAP query. This allows a caller with valid credentials for one LDAP directory entry to authenticate through APISIX as a consumer mapped to a different entry, bypassing the restrictions intended by the plugin's configured scope.
Recommendations Upgrade to version 3.18.0.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APISIX-2026-75020
CVE-2026-75020

Affected Products

Apache Apisix