LDAP Injection Vulnerability in Drupal LDAP / Active Directory Integration
CVE-2026-81205

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81205?

A vulnerability exists in the LDAP / Active Directory Integration for Drupal that allows attackers to manipulate LDAP queries through improper neutralization of user-supplied input. This can lead to unauthorized access or retrieval of sensitive data. Affected versions range from 0.0.0 to 2.2.1, necessitating immediate attention and remediation to safeguard against potential exploitation.

Affected Version(s)

LDAP / Active Directory Integration 0.0.0 < 2.2.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcus Johansson (marcus_johansson)
Harshvardhan Soni (sharsh)
Sudhanshu Dhage (sudhanshu0542)
Swan Kalata (akalata)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Jess (xjm)
.