PT-2026-45722 · Yandex · Yandex Database

CVE-2026-10549

·

Published

2026-06-02

·

Updated

2026-06-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/AU:Y
Name of the Vulnerable Software and Affected Versions Yandex Database versions prior to 25.3.1.25
Description An LDAP filter injection allows a remote attacker with valid LDAP credentials to bypass group membership checks, which results in unauthorized access to the database. LDAP filter injection occurs when an application fails to properly sanitize user-supplied input used to construct an LDAP query, allowing an attacker to alter the query logic.
Recommendations Update to version 25.3.1.25.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10549

Affected Products

Yandex Database