CVE-2026-53658
Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDAP uid search UserFilter without escaping LDAP metacharacters. An unauthenticated attacker with network access to the CA enrollment endpoint can alter the LDAP search before password validation and potentially steer authentication attempts toward a victim account. Deployments that do not use an LDAP backend are unaffected. This issue is fixed in version 1.5.21.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-90
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- hyperledger fabric-ca
Weakness type
Related vulnerabilities
- CVE-2024-56841 — A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab
- CVE-2026-33289 — SuiterCRM has LDAP Filter Injection in Authentication Module
- CVE-2019-11277 — Volume Services is vulnerable to an LDAP injection attack
- CVE-2021-41232 — Improper Neutralization of Special Elements used in an LDAP Query
- CVE-2026-46619 — OpenAM Authentication Bypass via MSISDN LDAP Injection
- CVE-2023-28853 — Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
- CVE-2020-5246 — LDAP injection vulnerability in Traccar GPS Tracking System
- CVE-2023-29050 — The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to ac