PatchSiren cyber security CVE debrief
CVE-2026-90979 Apache Software Foundation CVE debrief
A vulnerability in LDAPCache and LDAPBackingEngine allows for LDAP search filter injection through unescaped login names, potentially leading to over-granting of roles or incorrect login resolution. This issue arises from insufficient sanitization of login names, allowing crafted usernames to alter the structure of LDAP search filters. The vulnerability affects systems using GSSAPILdapLoginModule or LDAPBackingEngine directly, and defenders should prioritize verifying and patching affected systems.
- Vendor
- Apache Software Foundation
- Product
- Apache Karaf
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-28
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-28
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for LDAP-based authentication and role management systems should assess exposure and prioritize patching or mitigation. This includes administrators of systems using GSSAPILdapLoginModule or LDAPBackingEngine directly, as well as security teams managing LDAP filter templates and login activities.
Why it matters
CVE-2026-90979 is a vulnerability in LDAPCache and LDAPBackingEngine that allows for LDAP search filter injection, potentially leading to over-granting of roles or incorrect login resolution. Defenders should prioritize verifying and patching affected systems, especially those using GSSAPILdapLoginModule or LDAPBackingEngine directly. Evidence is limited, and further verification is required to determine affected versions and exploitation.
- Potential for unauthorized role escalation through LDAP search filter manipulation.
- Possible incorrect login resolution due to filter structure alteration.
- Need for verification of affected versions and systems using GSSAPILdapLoginModule or LDAPBackingEngine directly.
- Priority for updating LDAP filter templates and monitoring login activities.
Technical summary
LDAPCache and LDAPBackingEngine build LDAP search filters by textually substituting placeholders with user input. Before the fix, only double backslash escaping was applied, which does not escape RFC 4515 required characters (*, (, ), and NUL). This allows a crafted username to alter the filter structure, potentially widening search results and over-granting roles. The issue affects systems using GSSAPILdapLoginModule or LDAPBackingEngine directly, and defenders should prioritize verifying and patching affected systems.
Defensive priority
Defenders should prioritize verifying and patching affected systems, especially those using GSSAPILdapLoginModule or LDAPBackingEngine directly.
Recommended defensive actions
- Verify and apply patches for affected systems, especially those using GSSAPILdapLoginModule or LDAPBackingEngine directly.
- Review and update LDAP filter templates to ensure proper escaping of special characters.
- Monitor login and role lookup activities for potential anomalies.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and vendor information indicate a potential vulnerability in LDAP search filter handling. Details on affected versions and exploitation are limited, but defenders should verify and patch affected systems, especially those using GSSAPILdapLoginModule or LDAPBackingEngine directly. Evidence is limited, and further verification is required to determine affected versions and exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90979 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90979
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90979 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90979
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://karaf.apache.org/security/cve-2026-90979.txt
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.