CVE-2026-44930
Critical · CVSS 9.8Apache CXF — LDAP Injection
- CVSS
- 9.8
- nvd
- EPSS
- 0.72%
- 50th pct
- KEV
- No
- Class
- oss containerizable
- CWE-90, CWE-90
Description
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Search profile — drives PoC discovery
Symbols XKMSLDAPCertificateRepositoryXKMSServiceldapcertificateCXFLdapgetLdapCertificateldapCertRepo
Keywords CVE-2026-44930Apache CXFLDAP injectionXKMS serverLDAP Certificate repositoryCXF XKMS LDAPCWE-90arbitrary certificate retrieval
Versions: < 3.6.11, < 4.1.6, < 4.2.1
Affected packages
| Maven | org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap | 0 → 3.6.11 |
| Maven | org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap | 4.1.0 → 4.1.6 |
| Maven | org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap | 4.2.0 → 4.2.1 |
References
- https://lists.apache.org/thread/c1zqxppo1m5z3kbdhjn5p991zk09ynkh
- http://www.openwall.com/lists/oss-security/2026/05/22/9
- https://access.redhat.com/errata/RHSA-2026:37390
- https://access.redhat.com/security/cve/CVE-2026-44930
- https://bugzilla.redhat.com/show_bug.cgi?id=2480728
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44930.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z