CVE-2026-44671
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames before incorporating them into LDAP search filters. This allows unauthenticated attackers to perform LDAP Filter Injection during the login process. While this vulnerability does not allow for a full authentication bypass, an attacker can use LDAP metacharacters (such as *, (, )) to perform blind LDAP injection. By observing the different failure (or success) responses, an attacker can systematically enumerate valid usernames and extract sensitive attribute data from the connected LDAP directory. This vulnerability is fixed in 3.4.10 and 4.15.0.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.48%
- CWE
- CWE-90
- Published
- 2026-05-14
- Last modified
- 2026-05-15
Affected products
- zitadel zitadel
- zitadel zitadel
Weakness type
Related vulnerabilities
- CVE-2026-80055 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-78579 — Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
- CVE-2026-81205 — LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115
- CVE-2026-75020 — Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
- CVE-2026-19271 — Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
- CVE-2026-76373 — Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR
- CVE-2026-19930 — Dolibarr User Cloning card.php ldap injection
- CVE-2026-74241 — Quay: ldap referral filter injection in quay external ldap authentication