Description
Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API.



A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed.



This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.



Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Data Exposure
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows sensitive LDAP data to be transmitted in cleartext after initiating a StartTLS operation. An attacker who can observe traffic between the LDAP client and server can read authentication credentials or query responses before the TLS handshake is fully established. The weakness is an exposure of sensitive information to an unauthorized target, consistent with CWE-345. The effect is a confidentiality break that could compromise sensitive organizational data.

Affected Systems

Affected systems are Apache Directory LDAP API versions from 2.1.0 through 2.1.8. The products are listed under Apache Software Foundation:Apache Directory LDAP API. Clients and servers using these versions may be vulnerable when a Search request is sent and a StartTLS extended operation begins before the handshake completes.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network man‑in‑the‑middle that can capture traffic between client and server. The risk is moderate to high in environments where LDAP traffic is not otherwise encrypted, and mitigation requires updating to 2.1.9 or applying a workaround to avoid plaintext traffic during the handshake.

Generated by OpenCVE AI on October 2, 2026 at 11:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Directory LDAP API to version 2.1.9 or later.
  • If cannot be performed immediately, reconfigure client applications to initiate the StartTLS operation before any LDAP search requests are sent, thereby preventing the short window of plaintext transmission.
  • Monitor network traffic for unexpected plaintext LDAP data around the StartTLS handshake to detect any accidental transmission.

Generated by OpenCVE AI on October 2, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache directory Ldap Api
Vendors & Products Apache
Apache directory Ldap Api

Fri, 02 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Title Apache Directory LDAP API: Injection of plaintext responses during StartTLS
Weaknesses CWE-345
References

Subscriptions

Apache Directory Ldap Api
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:02:38.002Z

Reserved: 2026-10-01T12:58:16.190Z

Link: CVE-2026-103878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:06.570

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-103878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity