LDAP Injection Vulnerability in Netatalk Affects Versions 2.1.0 to 4.4.2
CVE-2026-44063

4.2MEDIUM

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-44063?

An LDAP injection vulnerability exists in Netatalk versions 2.1.0 through 4.4.2, enabling an authenticated remote attacker to exploit crafted LDAP filter inputs. This flaw could permit unauthorized access to limited information or allow modification of LDAP entries, posing a risk to system integrity and confidentiality. Proper validation and sanitization of inputs can help mitigate this issue.

Affected Version(s)

Netatalk 2.1.0 <= 4.4.2

Netatalk 4.5.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.