LDAP injection in Central Dogma - CVE-2026-11748
Published: June 23, 2026
Central Dogma
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication controls and evade audit logging.
The vulnerability exists due to LDAP injection in SearchFirstActiveDirectoryRealm.findUserDn() when processing a user-supplied username in an LDAP search filter. A remote attacker can submit a specially crafted username to bypass authentication controls and evade audit logging.
Only deployments that use the opt-in Active Directory search-first realm are vulnerable; the shipped DefaultLdapRealm example configuration is not affected.