Improper validation of certificate with host mismatch in Directory LDAP API - CVE-2026-35563
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote user to impersonate an LDAP server and compromise the connection.
The vulnerability exists due to improper validation of certificate with host mismatch in the LDAP client implementation when establishing TLS-protected LDAP connections. A remote user can present a valid certificate for an unrelated host to impersonate an LDAP server and compromise the connection.
Exploitation requires man-in-the-middle capability on the network and a certificate trusted by the client\'s configured trust store.
Affected software
Keycloak
How to mitigate CVE-2026-35563
Keycloak - update to 26.7.3