Deserialization Vulnerability in Apache Directory LDAP API
CVE-2026-103877

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-103877?

A vulnerability exists in the Apache Directory LDAP API that allows a rogue or compromised LDAP server to respond to client loadSchema() requests with a maliciously constructed schema object containing a serialized Java class. This can lead to potential remote code execution (RCE) risks. Users are strongly encouraged to upgrade to version 2.1.9 to address this security issue.

Affected Version(s)

Apache Directory LDAP API 2.1.0 < 2.1.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security
The Apache Software Foundation
.