SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13608

HIGH · CVSS 7.4 EPSS 0.64%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the libcurl library's SASL negotiation for LDAP authentication permits an incomplete handshake to be incorrectly recognized as a successful cryptographic verification. This flaw enables an attacker to perform a Man-in-the-Middle (MITM) attack, potentially allowing them to bypass essential peer validation. Organizations utilizing libcurl for LDAP authentication should prioritize addressing this issue to mitigate the risk of unauthorized access and data compromise.

CVE
CVE-2026-13608
Severity
HIGH
CVSS
7.4
EPSS
0.64%

Original NVD Description

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)