CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-44930 — An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s...

·Source: NIST NVD

Updated:

Executive Summary

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Analysis

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue. CVSS Score: 9.8. Published: 2026-05-22T13:16:22.820.

Indicators of Compromise (1)

CVE (1)
CVE-2026-44930
Source Attribution

Originally published by NIST NVD on May 22, 2026. Verified by: NIST.

Related Threats