Improper Authentication in Spring LDAP - CVE-2026-41720

 

Improper Authentication in Spring LDAP - CVE-2026-41720

Published: August 28, 2026


Vulnerability identifier: #VU146175
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41720
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass password verification.

The vulnerability exists due to improper authentication in DirContextAuthenticationStrategy implementations when processing a bind request with a non-empty username and an empty or null password. A remote attacker can submit such a bind request to bypass password verification.

Exploitation depends on an LDAP server configuration that permits unauthenticated binds.


Affected software

Spring LDAP

How to mitigate CVE-2026-41720

Install security update from vendor's website.

Spring LDAP - addressed in versions 2.4.5, 3.2.18, 3.3.8, 4.0.4

External References

Related Security Bulletins