AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2021-38266

HIGH · CVSS 7.5 EPSS 1.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-03-02 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.

CVE
CVE-2021-38266
Severity
HIGH
CVSS
7.5
EPSS
1.73%

Original NVD Description

The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.

Related CVEs

Other vulnerabilities affecting the same vendor(s)