Sensitive Data Transmission Issue in Apache Directory LDAP API
CVE-2026-103878
Currently unrated
What is CVE-2026-103878?
A vulnerability in the Apache Directory LDAP API exists due to cleartext transmission of sensitive information. When a StartTLS extended operation is initiated following a Search request, it may allow the retrieval of data in plaintext format before the TLS handshake has been completed. This can expose sensitive data to interception and unauthorized access. Users are strongly advised to upgrade to version 2.1.9 or later to mitigate this issue.
Affected Version(s)
Apache Directory LDAP API 2.1.0 < 2.1.9