PT-2026-45280 · Apache · Apache Directory Ldap Api

Łukasz Kollbek

+1

·

Published

2026-06-01

·

Updated

2026-06-02

·

CVE-2026-35563

CVSS v4.0

8.8

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Apache Directory LDAP API version 2.1.7
Description The LDAP client implementation fails to verify if the server certificate matches the intended LDAP hostname. Although the certificate chain is validated against a trusted authority, the lack of endpoint identification allows a valid certificate issued for an unrelated host to be accepted. This flaw enables server impersonation and complete connection compromise if an attacker with Man-in-the-Middle (MITM) capabilities presents a certificate trusted by the client's trust store.
Recommendations Update to the new version of the LDAP API where hostname verification is enforced.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35563

Affected Products

Apache Directory Ldap Api