CWE-90Base

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Draft in the CWE catalog · 66 CVEs mapped

66
CVEs mapped
6.5
Median CVSS
What it is

The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

Recent examples
5.3cvss
CVE-2026-81205

CVE-2026-81205 - MEDIUM Severity Vulnerability

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

MEDIUMno explanation yet
0%
epss
8.1cvss
CVE-2026-75020

CVE-2026-75020 - HIGH Severity Vulnerability

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach. This issue affects Apache APISIX: from 2.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

HIGHno explanation yet
1%
epss
7.5cvss
CVE-2026-19271

CVE-2026-19271 - HIGH Severity Vulnerability

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection. This issue affects Liderahenk: from 3.4.0 before 3.5.5.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-90
Abstraction
Base
Structure
Simple
Status
Draft