Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 7 min 98 bronnen 3 kritiek 34 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2026-75020

HIGH · 8.1 CVSS Gepubliceerd: CWE-90

Beschrijving

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX.

A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach.

This issue affects Apache APISIX: from 2.11.0 through 3.17.0.

Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Vendors

Apache

Affected products

Apisix

References