Beveiligingsadvies

CVE-2026-40459

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-17 13:18:39
Laatst bijgewerkt 2026-04-17 13:54:22
Toegewezen door CERT-PL
CVSS-score 8.7
Status PUBLISHED

Beschrijving

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1