LDAP Injection Vulnerability in Central Dogma Server by LINE Corporation
CVE-2026-11748
6.9MEDIUM
What is CVE-2026-11748?
A vulnerability exists in the Central Dogma Server, specifically in the centraldogma-server-auth-shiro component prior to version 0.84.0. This issue arises when the SearchFirstActiveDirectoryRealm incorrectly processes login usernames within an LDAP search filter without properly sanitizing LDAP metacharacters. As a result, an unauthenticated attacker may exploit this flaw to manipulate the LDAP filter, leading to authentication confusion and the potential to enumerate sensitive directory information.
Affected Version(s)
Central Dogma 0.84.0
