Security Advisory

CVE-2026-10549

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-02 08:27:06
Last updated 2026-06-02 13:30:02
Assigner yandex
CVSS score not scored
State PUBLISHED

Description

LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database.