SB2026090403 - MitM attack in Apache Directory LDAP API
Published: September 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper validation of certificate with host mismatch (CVE-ID: CVE-2026-35563)
CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch
CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to impersonate an LDAP server and compromise the connection.
The vulnerability exists due to improper validation of certificate with host mismatch in the LDAP client implementation when establishing TLS-protected LDAP connections. A remote user can present a valid certificate for an unrelated host to impersonate an LDAP server and compromise the connection.
Exploitation requires man-in-the-middle capability on the network and a certificate trusted by the client\'s configured trust store.
Remediation
Install update from vendor's website.