SB2026090403 - MitM attack in Apache Directory LDAP API



SB2026090403 - MitM attack in Apache Directory LDAP API

Published: September 4, 2026

Security Bulletin ID SB2026090403
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper validation of certificate with host mismatch (CVE-ID: CVE-2026-35563)

CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch

CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to impersonate an LDAP server and compromise the connection.

The vulnerability exists due to improper validation of certificate with host mismatch in the LDAP client implementation when establishing TLS-protected LDAP connections. A remote user can present a valid certificate for an unrelated host to impersonate an LDAP server and compromise the connection.

Exploitation requires man-in-the-middle capability on the network and a certificate trusted by the client\'s configured trust store.


Remediation

Install update from vendor's website.