LDAP Authentication Flaw in Red Hat Quay
CVE-2026-74241
4.8MEDIUM
What is CVE-2026-74241?
A vulnerability has been identified in Red Hat Quay's handling of Lightweight Directory Access Protocol (LDAP) authentication. The flaw arises when LDAP referrals return during authentication processes, where the username input is not correctly escaped. This oversight can lead to the injection of LDAP filter metacharacters, allowing attackers to exploit user-existence oracle attacks at the referred Directory Name (DN). Additionally, this vulnerability may impact the integrity of DN utilized for password binding in multi-domain Active Directory configurations.
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank meifukun (https://github.com/meifukun) for reporting this issue.