LDAP Search Filter Vulnerability in Apache Karaf
CVE-2026-90979
What is CVE-2026-90979?
The LDAP search filter implementation in Apache Karaf's LDAPCache and LDAPBackingEngine is susceptible to a vulnerability that allows crafted user input to manipulate LDAP filter structures. Specifically, the system fails to adequately escape certain characters required by RFC 4515, such as '*', '(', ')', and NUL, resulting in potential misinterpretation of user roles and unauthorized access grants. This flaw can lead to unintended LDAP entries being matched, which compromises user authentication and role assignments. While certain login modules apply proper encoding measures, direct access to LDAPCache can expose this vulnerability, emphasizing the need for cautious implementation when leveraging LDAP in Apache Karaf.
Affected Version(s)
Apache Karaf 0 < 4.4.12