CWE-90: LDAP Injection
The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
68 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-56841 — A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab
- CVE-2026-33289 — SuiterCRM has LDAP Filter Injection in Authentication Module
- CVE-2026-41919 — Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
- CVE-2026-49268 — Apache Shiro: LDAP DN Injection in DefaultLdapRealm
- CVE-2026-13696 — LDAP Injection in HAVELSAN's Liman MYS
- CVE-2026-58222 — Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes
- CVE-2026-39962 — LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
- CVE-2026-25560 — WeKan < 8.19 LDAP Authentication Filter Injection
- CVE-2026-40459 — LDAP Injection in PAC4J
- CVE-2026-4256 — LDAP Injection in PEAKUP's PassGate
- CVE-2026-40193 — Maddy Mail Server: LDAP Filter Injection via Unsanitized Username
- CVE-2026-34578 — OPNsense has an LDAP Injection via Unsanitized Username in Authentication
- CVE-2026-44304 — Lemur: LDAP Filter Injection enables post-authentication privilege escalation
- CVE-2025-52575 — EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements
- CVE-2025-27631 — The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code in
- CVE-2026-33751 — n8n Vulnerable to LDAP Filter Injection in LDAP Node
- CVE-2026-29138 — PGP Decryption Sender LDAP Injection
- CVE-2026-11770 — 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
- CVE-2026-44671 — ZITADEL: LDAP Filter Injection in Login Flow
- CVE-2026-19271 — Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
Recently published
- CVE-2026-80055 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78579 — Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
- CVE-2026-81205 — LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115
- CVE-2026-75020 — Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
- CVE-2026-19271 — Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
- CVE-2026-76373 — Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR
- CVE-2026-19930 — Dolibarr User Cloning card.php ldap injection
- CVE-2026-74241 — Quay: ldap referral filter injection in quay external ldap authentication
- CVE-2026-16071 — Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
- CVE-2026-59652 — LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
- CVE-2026-11770 — 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
- CVE-2026-44617 — Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
- CVE-2026-44616 — Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
- CVE-2026-58222 — Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes
- CVE-2026-4256 — LDAP Injection in PEAKUP's PassGate
- CVE-2026-13696 — LDAP Injection in HAVELSAN's Liman MYS
- CVE-2026-49268 — Apache Shiro: LDAP DN Injection in DefaultLdapRealm
- CVE-2026-42568 — Yamcs Vulnerable to LDAP Injection in LdapAuthModule
- CVE-2026-45559 — Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only)
- CVE-2026-46745 — Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token