LDAP Injection Vulnerability in Central Dogma Server by LINE Corporation
CVE-2026-11748

6.9MEDIUM

Key Information:

Vendor
CVE Published:
22 June 2026

What is CVE-2026-11748?

A vulnerability exists in the Central Dogma Server, specifically in the centraldogma-server-auth-shiro component prior to version 0.84.0. This issue arises when the SearchFirstActiveDirectoryRealm incorrectly processes login usernames within an LDAP search filter without properly sanitizing LDAP metacharacters. As a result, an unauthenticated attacker may exploit this flaw to manipulate the LDAP filter, leading to authentication confusion and the potential to enumerate sensitive directory information.

Affected Version(s)

Central Dogma 0.84.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.