PT-2026-42409 · Netatalk · Netatalk

Arjun Basnet

·

Published

2026-05-21

·

Updated

2026-05-21

·

CVE-2026-44052

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Netatalk versions 2.1.0 through 4.4.2
Description Netatalk inserts LDAP simple-bind passwords into log output in cleartext. This allows an attacker with access to the log files to obtain LDAP credentials.
Recommendations Update to version 4.4.3.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2026-44052

Affected Products

Netatalk