Description
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Drupal LDAP / Active Directory Integration contains an LDAP Injection flaw caused by improper neutralization of special elements in LDAP queries, which allows attackers to inject arbitrary LDAP statements. The vulnerability can lead to the unauthorized disclosure of directory information, potentially exposing sensitive organizational data for sites that rely on LDAP authentication. Based on the description, it is inferred that the impact primarily affects confidentiality, enabling an attacker to read data not intended for public consumption.

Affected Systems

The Drupal LDAP / Active Directory Integration module is affected for all versions ranging from 0.0.0 up to and including 2.2.1. Any Drupal site that has this module installed within that version window is susceptible to attack and may expose its LDAP directory data to malicious actors.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The exploit is a classic LDAP injection that can be performed when an attacker can influence input that is incorporated into an LDAP query. Because no EPSS score is available and the issue is not listed in CISA KEV, the likelihood of widespread exploitation is currently low, but the vector remains active and could be leveraged by adversaries with the necessary access to the vulnerable forms or inputs."

Generated by OpenCVE AI on September 3, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal LDAP / Active Directory Integration to version 2.2.2 or later when the patch becomes available
  • Implement proper input validation or parameterized LDAP queries in any custom code that interacts with the LDAP module to prevent injection attempts
  • Monitor LDAP logs and audit trails for abnormal query patterns that could indicate injection activity

Generated by OpenCVE AI on September 3, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange
Miniorange ldap \/ Active Directory Integration
CPEs cpe:2.3:a:miniorange:ldap_\/_active_directory_integration:*:*:*:*:*:drupal:*:*
Vendors & Products Miniorange
Miniorange ldap \/ Active Directory Integration

Wed, 02 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal ldap / Active Directory Integration
Vendors & Products Drupal
Drupal ldap / Active Directory Integration

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
Title LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115
Weaknesses CWE-90
References

Subscriptions

Drupal Ldap / Active Directory Integration
Miniorange Ldap \/ Active Directory Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T19:10:24.348Z

Reserved: 2026-08-26T16:42:57.131Z

Link: CVE-2026-81205

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T13:18:12.803

Modified: 2026-09-16T15:43:37.810

Link: CVE-2026-81205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:30:12Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')