Description
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API.



A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE. 



This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.



Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Apache Directory LDAP API has a deserialization flaw that allows an attacker to inject a serialized Java class through the loadSchema() subschema search. When an LDAP server or a pre‑TLS man‑in‑the‑mid‑point returns a schema object containing that class, the client deserializes it without validation, potentially leading to remote code execution on the system hosting the API. This vulnerability is identified as CWE‑502 and can compromise the confidentiality, integrity, and availability of the affected application.

Affected Systems

The flaw exists in Apache Directory LDAP API versions from 2.1.0 up through 2.1.8 inclusive. Any deployment that uses these releases and performs loadSchema() requests against an LDAP server that is not strictly trusted is vulnerable. The issue does not affect releases prior to 2.1.0 or the patched 2.1.9 variant.

Risk and Exploitability

An attacker can exploit the vulnerability by controlling an LDAP server or positioning a pre‑TLS interception that supplies a malicious schema during a loadSchema() call. While no CVSS score or EPSS value is published, the absence of a KEV listing suggests it has not yet been actively exploited. Nevertheless, the payload can grant arbitrary code execution; therefore the potential impact is severe. Mitigation relies on upgrading to 2.1.9, using TLS, and ensuring only trusted servers are queried.

Generated by OpenCVE AI on October 2, 2026 at 11:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Directory LDAP API to version 2.1.9 or later, which removes the vulnerable schema deserialization.
  • Configure the client to use TLS when connecting to LDAP servers, preventing untrusted servers or MITM from supplying malicious schema.
  • Enforce strict authentication and restrict LDAP connections to trusted servers only, mitigating rogue server attacks.

Generated by OpenCVE AI on October 2, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache directory Ldap Api
Vendors & Products Apache
Apache directory Ldap Api

Fri, 02 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE.  This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Title Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements
Weaknesses CWE-502
References

Subscriptions

Apache Directory Ldap Api
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:08:42.494Z

Reserved: 2026-10-01T12:43:28.815Z

Link: CVE-2026-103877

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:06.437

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-103877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data