CVE-2026-44930
EUVD-2026-3143322.05.2026, 13:16
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | cxf | 𝑥 < 3.6.11 |
| apache | cxf | 4.0.0 ≤ 𝑥 < 4.1.6 |
| apache | cxf | 4.2.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 | repo-ldap ≤ 𝑥 < * | ADP |
References