Apache CXF LDAP Injection Flaw Exposes Arbitrary Certificates
ID: 994be7fc-890e-5410-b833-4ff62d36e35d
STIX ID: report--994be7fc-890e-5410-b833-4ff62d36e35d
Feed Name: Cyber Press
Threat Score
Apache Software Foundation patched a critical LDAP injection vulnerability (CVE-2026-44930) in Apache CXF's XKMS LDAP Certificate Repository that could allow remote attackers to retrieve arbitrary X.509 certificates (CVSS 3.1 score 9.8); administrators are advised to immediately upgrade affected CXF branches to 4.2.1, 4.1.6, or 3.6.11, audit LDAP logs for anomalous filters, and review two companion fixes (an XXE and an incomplete RCE fix).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
