AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-4256

HIGH · CVSS 8.2 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

PassGate by PEAKUP Technology Inc. is vulnerable to LDAP injection due to improper neutralization of special elements in LDAP queries, allowing attackers to manipulate queries and potentially access sensitive data. The high severity of this vulnerability (CVSS 8.2) necessitates immediate attention from organizations using PassGate, particularly those handling sensitive user information or authentication processes. Prioritization is crucial to mitigate the risk of unauthorized access and data breaches.

CVE
CVE-2026-4256
Severity
HIGH
CVSS
8.2
EPSS
0.21%

Original NVD Description

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026.