PT-2026-4310 · Kipper+1 · Kipper+1

Solovvway

·

Publicado

2026-01-22

·

Atualizado

2026-02-27

·

CVE-2026-24130

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moonraker versions 0.9.3 and below
Description Moonraker is a Python web server providing API access to Klipper 3D printing firmware. When the ldap component is enabled, instances are susceptible to LDAP search filter injection via the ''login'' endpoint. An attacker can leverage the 401 error response to confirm successful searches, enabling brute-force attempts to uncover LDAP entries, including user IDs and attributes. The ''login'' endpoint is the point of exploitation. The ldap component is the vulnerable component.
Recommendations Upgrade to Moonraker version 0.10.0. As a temporary workaround, set the max login attempts option in the [authorization] section of moonraker.conf to a reasonable value. As a more secure workaround, remove the ldap section from moonraker.conf and rely on the built-in user authentication.

Exploit

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24130
GHSA-3JQF-V4MV-747G

Produtos afetados

Kipper
Moonraker