SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81205

MEDIUM · CVSS 5.3 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in Drupal's LDAP / Active Directory Integration allows for LDAP Injection due to improper neutralization of special elements in LDAP queries, potentially enabling attackers to manipulate queries and gain unauthorized access to sensitive information. Organizations using affected versions (0.0.0 to 2.2.1) should prioritize remediation to mitigate the risk of data exposure and unauthorized actions within their directory services. This is particularly critical for environments relying on LDAP for authentication and user management.

CVE
CVE-2026-81205
Severity
MEDIUM
CVSS
5.3
EPSS
0.33%

Original NVD Description

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)