LDAP injection in Apache APISIX - CVE-2026-75020

 

LDAP injection in Apache APISIX - CVE-2026-75020

Published: August 27, 2026


Vulnerability identifier: #VU145878
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-75020
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to impersonate another identity.

The vulnerability exists due to improper neutralization of special elements used in an LDAP query in the ldap-auth plugin when authenticating against the LDAP directory. A remote user can supply crafted credentials to impersonate another identity.

The issue affects consumer mapping across LDAP subtrees that were intended to be outside the configured scope.


Affected software

Apache APISIX

How to mitigate CVE-2026-75020

Install security update from vendor's website.

Apache APISIX - update to 3.18.0

External References

Related Security Bulletins