Description
Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDAP uid search UserFilter without escaping LDAP metacharacters. An unauthenticated attacker with network access to the CA enrollment endpoint can alter the LDAP search before password validation and potentially steer authentication attempts toward a victim account. Deployments that do not use an LDAP backend are unaffected. This issue is fixed in version 1.5.21.
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: LDAP Injection affecting authentication steering
Action: Immediate Patch
AI Analysis

Impact

Fabric CA, the Certificate Authority used in Hyperledger Fabric, has a flaw in its Client.GetUser function when an LDAP backend is active. The username supplied by HTTP Basic authentication is embedded directly into the LDAP uid UserFilter without escaping LDAP metacharacters. An unauthenticated attacker with network access to the CA enrollment endpoint can alter this filter before the password check and potentially redirect authentication attempts toward a victim account.

Affected Systems

Versions of hyperledger fabric-ca older than 1.5.21 that are configured to use an LDAP backend are vulnerable. Deployments running the patched 1.5.21 release or those that do not use LDAP for identity management are not affected.

Risk and Exploitability

The CVSS base score of 6.3 indicates a moderate threat level. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, suggesting a very low probability of widespread automated exploitation. The vulnerability can be exploited by any actor with network access to the CA enrollment endpoint by sending a crafted HTTP request; no additional privileges are needed, making the attack relatively straightforward for an exposed deployment.

Generated by OpenCVE AI on September 20, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Fabric CA to version 1.5.21 or later, which applies proper escaping to the LDAP search filter.
  • If an upgrade cannot be performed immediately, limit network exposure to the CA enrollment endpoint by using firewall rules or network segmentation so that only trusted hosts can reach the endpoint.
  • Verify that the LDAP backend is correctly configured, audit LDAP query handling to ensure proper sanitization of user input, and remove or disable the LDAP backend if it is not required for the deployment.

Generated by OpenCVE AI on September 20, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xghw-p77p-3r7x Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDAP uid search UserFilter without escaping LDAP metacharacters. An unauthenticated attacker with network access to the CA enrollment endpoint can alter the LDAP search before password validation and potentially steer authentication attempts toward a victim account. Deployments that do not use an LDAP backend are unaffected. This issue is fixed in version 1.5.21.
Title Fabric CA: LDAP Injection via Unescaped Username in GetUser Filter
Weaknesses CWE-90
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:37:16.265Z

Reserved: 2026-06-09T20:50:36.877Z

Link: CVE-2026-53658

cve-icon Vulnrichment

Updated: 2026-09-16T15:37:13.424Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T17:17:18.943

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-53658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')