PT-2026-99838 · Unknown+1 · Ldapbackingengine+1
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
LDAPCache and LDAPBackingEngine (affected versions not specified)
Description
LDAPCache and LDAPBackingEngine build LDAP search filters for user and role lookups by substituting placeholders
%u, %dn, and %fqdn into administrator-configured filter templates userFilter and roleFilter. The software fails to properly escape characters required by RFC 4515, specifically *, (, ), and NUL. A crafted login name containing these characters can alter the structure of the resulting filter, potentially turning an equality match into a wildcard match or closing and reopening filter clauses. This can lead to the search returning unintended LDAP entries, resulting in over-granted roles or affecting which account a login resolves to. This issue is specifically reproducible through the GSSAPILdapLoginModule via the NameCallback name and through the LDAPBackingEngine listRoles() function using principal.getName(), as these paths do not apply prior escaping.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ldapbackingengine
Ldapcache