Improper Authentication in Spring LDAP - CVE-2026-41720
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass password verification.
The vulnerability exists due to improper authentication in DirContextAuthenticationStrategy implementations when processing a bind request with a non-empty username and an empty or null password. A remote attacker can submit such a bind request to bypass password verification.
Exploitation depends on an LDAP server configuration that permits unauthenticated binds.