PT-2026-45722 · Yandex · Yandex Database
CVE-2026-10549
·
Published
2026-06-02
·
Updated
2026-06-02
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/AU:Y |
Name of the Vulnerable Software and Affected Versions
Yandex Database versions prior to 25.3.1.25
Description
An LDAP filter injection allows a remote attacker with valid LDAP credentials to bypass group membership checks, which results in unauthorized access to the database. LDAP filter injection occurs when an application fails to properly sanitize user-supplied input used to construct an LDAP query, allowing an attacker to alter the query logic.
Recommendations
Update to version 25.3.1.25.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yandex Database