CVE-2026-19271CWE-90

CVE-2026-19271

High · published August 26, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
22.6
In the wild
Unconfirmed
What it is

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection.

This issue affects Liderahenk: from 3.4.0 before 3.5.5.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00303 · 22.6th percentile
Weakness
CWE-90 · Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
Published
2026-08-26T18:17Z
References (1)
EPSS history
Timeline
  • 28 AUG 06:32Z
    EPSS moved — → 0%
    epss
  • 26 AUG 13:44Z
    Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
    cvelistv5