LDAP Authentication Flaw in Red Hat Quay
CVE-2026-74241

4.8MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
14 August 2026

What is CVE-2026-74241?

A vulnerability has been identified in Red Hat Quay's handling of Lightweight Directory Access Protocol (LDAP) authentication. The flaw arises when LDAP referrals return during authentication processes, where the username input is not correctly escaped. This oversight can lead to the injection of LDAP filter metacharacters, allowing attackers to exploit user-existence oracle attacks at the referred Directory Name (DN). Additionally, this vulnerability may impact the integrity of DN utilized for password binding in multi-domain Active Directory configurations.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank meifukun (https://github.com/meifukun) for reporting this issue.
.