PT-2026-45280 · Apache · Apache Directory Ldap Api
Łukasz Kollbek
+1
·
Published
2026-06-01
·
Updated
2026-06-02
·
CVE-2026-35563
CVSS v4.0
8.8
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Apache Directory LDAP API version 2.1.7
Description
The LDAP client implementation fails to verify if the server certificate matches the intended LDAP hostname. Although the certificate chain is validated against a trusted authority, the lack of endpoint identification allows a valid certificate issued for an unrelated host to be accepted. This flaw enables server impersonation and complete connection compromise if an attacker with Man-in-the-Middle (MITM) capabilities presents a certificate trusted by the client's trust store.
Recommendations
Update to the new version of the LDAP API where hostname verification is enforced.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Directory Ldap Api