OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103878

HIGH · CVSS 7.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Apache Directory LDAP API versions prior to 2.1.9 are vulnerable to a cleartext transmission issue, where sensitive information can be exposed during a StartTLS operation initiated after a Search request, before the TLS handshake is finalized. This vulnerability could lead to unauthorized access to sensitive data. Organizations using affected versions should prioritize upgrading to 2.1.9 to mitigate this risk.

CVE
CVE-2026-103878
Severity
HIGH
CVSS
7.5
EPSS
0.21%
Apache

Original NVD Description

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.