CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-44930

Critical · CVSS 9.8

Apache CXF — LDAP Injection

CVSS
9.8
nvd
EPSS
0.72%
50th pct
KEV
No
Class
oss containerizable
CWE-90, CWE-90

Description

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Search profile — drives PoC discovery

Symbols XKMSLDAPCertificateRepositoryXKMSServiceldapcertificateCXFLdapgetLdapCertificateldapCertRepo
Keywords CVE-2026-44930Apache CXFLDAP injectionXKMS serverLDAP Certificate repositoryCXF XKMS LDAPCWE-90arbitrary certificate retrieval
Versions: < 3.6.11, < 4.1.6, < 4.2.1

Affected packages

Maven org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap 0 → 3.6.11
Maven org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap 4.1.0 → 4.1.6
Maven org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap 4.2.0 → 4.2.1

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z