Description
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection.

This issue affects Liderahenk: from 3.4.0 before 3.5.5.
Published: 2026-08-26
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an LDAP injection flaw in the sign‑in endpoint of Liderahenk that allows an attacker to supply unfiltered input, causing the server to execute malicious LDAP queries. Classified as CWE‑90, the flaw can enable an attacker to read sensitive directory entries, exfiltrate credentials, or bypass authentication requirements, leading to significant data exposure.

Affected Systems

Affected systems are TÜBİTAK BİLGEM’s Liderahenk versions from 3.4.0 through 3.5.4. The flaw resides in the sign‑in flow and impacts all deployments of these releases that rely on the default LDAP configuration.

Risk and Exploitability

The CVSS score of 7.5 marks this vulnerability as high impact. While EPSS is not published, the absence of a KEV listing indicates no known widespread exploitation to date. The likely attack vector is remote, involving crafted HTTP requests to the login service. Exploitation would require no privileged access but could be performed by an unauthenticated or low‑privilege attacker to read directory data or impersonate a user.

Generated by OpenCVE AI on August 26, 2026 at 16:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Liderahenk release 3.5.5 or newer to address the LDAP injection flaw.
  • Implement input validation and sanitization for all parameters used in LDAP queries, rejecting or escaping special characters such as * ( ) \, etc.
  • Configure the LDAP service to restrict query rights for unauthenticated users and enforce minimal necessary permissions on directory access.

Generated by OpenCVE AI on August 26, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection. This issue affects Liderahenk: from 3.4.0 before 3.5.5.
Title Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
Weaknesses CWE-90
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-26T15:43:48.093Z

Reserved: 2026-08-07T14:23:01.592Z

Link: CVE-2026-19271

cve-icon Vulnrichment

Updated: 2026-08-26T15:43:41.410Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T14:17:08.500

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-19271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T16:45:08Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')