SEPTEMBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-75020

HIGH · CVSS 8.1 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

Apache APISIX versions 2.11.0 through 3.17.0 are vulnerable to an LDAP injection flaw that allows authenticated users to bypass access controls and authenticate as different consumers within the LDAP directory. This vulnerability poses a significant risk as it can lead to unauthorized access to sensitive resources. Organizations using affected versions should prioritize upgrading to version 3.18.0 to mitigate this security risk.

CVE
CVE-2026-75020
Severity
HIGH
CVSS
8.1
EPSS
0.50%
Apache

Original NVD Description

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach. This issue affects Apache APISIX: from 2.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)