Description
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection.

This issue affects PassGate: through 30042026.
Published: 2026-07-09
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PEAKUP Technology Inc. PassGate contains an LDAP injection flaw where user-supplied input is inserted into an LDAP query CWE-90. The vulnerability enables manipulation of LDAP query syntax, and may lead to unauthorized retrieval or modification of directory entries - this is inferred from the description that the query can be altered, but the CVE data does not explicitly confirm the end result.

Affected Systems

All versions of PEAKUP PassGate through build 30042026 are affected, as noted by the vendor advisory.

Risk and Exploitability

The CVSS score of 8.2 signals high severity. The EPSS score is less than 1%, indicating a very low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread attacks yet. The likely attack vector involves network access to Pass LDAP queries can be submitted; this flaw that allows alteration of LDAP query syntax.

Generated by OpenCVE AI on July 26, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PassGate to a version newer than 30042026 to obtain the vendor patch.
  • If an immediate patch is not feasible, enforce strict input validation on all values that are incorporated into LDAP queries, escaping or rejecting characters that modify LDAP syntax.
  • Limit the LDAP service account used by PassGate to read-only operations and monitor LDAP logs for anomalous query activity.

Generated by OpenCVE AI on July 26, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Peakup Technology
Peakup Technology passgate
Vendors & Products Peakup Technology
Peakup Technology passgate

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026.
Title LDAP Injection in PEAKUP's PassGate
Weaknesses CWE-90
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Peakup Technology Passgate
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-09T13:42:03.407Z

Reserved: 2026-03-16T07:44:00.802Z

Link: CVE-2026-4256

cve-icon Vulnrichment

Updated: 2026-07-09T13:41:59.891Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T15:30:04Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')