PT-2026-99838 · Unknown+1 · Ldapbackingengine+1

·

CVE-2026-90979

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions LDAPCache and LDAPBackingEngine (affected versions not specified)
Description LDAPCache and LDAPBackingEngine build LDAP search filters for user and role lookups by substituting placeholders %u, %dn, and %fqdn into administrator-configured filter templates userFilter and roleFilter. The software fails to properly escape characters required by RFC 4515, specifically *, (, ), and NUL. A crafted login name containing these characters can alter the structure of the resulting filter, potentially turning an equality match into a wildcard match or closing and reopening filter clauses. This can lead to the search returning unintended LDAP entries, resulting in over-granted roles or affecting which account a login resolves to. This issue is specifically reproducible through the GSSAPILdapLoginModule via the NameCallback name and through the LDAPBackingEngine listRoles() function using principal.getName(), as these paths do not apply prior escaping.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90979

Affected Products

Ldapbackingengine
Ldapcache