Improper validation of certificate with host mismatch in Directory LDAP API - CVE-2026-35563

 

Improper validation of certificate with host mismatch in Directory LDAP API - CVE-2026-35563

Published: September 4, 2026


Vulnerability identifier: #VU146887
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35563
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to impersonate an LDAP server and compromise the connection.

The vulnerability exists due to improper validation of certificate with host mismatch in the LDAP client implementation when establishing TLS-protected LDAP connections. A remote user can present a valid certificate for an unrelated host to impersonate an LDAP server and compromise the connection.

Exploitation requires man-in-the-middle capability on the network and a certificate trusted by the client\'s configured trust store.


Affected software

Directory LDAP API
Keycloak

How to mitigate CVE-2026-35563

Install security update from vendor's website.

Directory LDAP API - update to 2.1.8
Keycloak - update to 26.7.3

External References

Related Security Bulletins