LDAP injection in Apache APISIX - CVE-2026-75020
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote user to impersonate another identity.
The vulnerability exists due to improper neutralization of special elements used in an LDAP query in the ldap-auth plugin when authenticating against the LDAP directory. A remote user can supply crafted credentials to impersonate another identity.
The issue affects consumer mapping across LDAP subtrees that were intended to be outside the configured scope.