logo

Apache CXF Flaw Exposes Systems to LDAP Injection Attacks

ID: a9f115fd-b756-52e0-aecd-f6325bede75c

STIX ID: report--a9f115fd-b756-52e0-aecd-f6325bede75c

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Divya

...
...

Apache CXF suffers an LDAP injection vulnerability (CVE-2026-44930) in the cxf-services-xkms-x509-repo-ldap component that can allow attackers to manipulate LDAP queries and retrieve arbitrary X.509 certificates, potentially compromising certificate-based trust; multiple CXF versions are affected and Apache has released patched versions (4.2.1, 4.1.6, 3.6.11).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.