PT-2026-7140 · Apache · Druid-Basic-Security+1

Karan Kumar

·

Published

2026-02-09

·

Updated

2026-02-17

·

CVE-2026-23906

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Druid versions 0.17.0 through 35.x
Description An authentication bypass issue exists in Apache Druid when the druid-basic-security extension is enabled with LDAP authentication. If the underlying LDAP server allows anonymous binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to Druid resources without valid credentials. The issue arises from improper validation of LDAP authentication responses when anonymous binds are permitted, treating anonymous bind success as valid user authentication. A remote, unauthenticated attacker can gain unauthorized access to the Druid cluster, access sensitive data, execute queries, potentially manipulate data, access administrative interfaces, and compromise the confidentiality, integrity, and availability of the deployment.
Recommendations Versions 0.17.0 through 35.x: Disable anonymous bind on your LDAP server. Versions 0.17.0 through 35.x: Upgrade to version 36.0.0 or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-23906
GHSA-Q672-HFC7-G833

Affected Products

Apache Druid
Druid-Basic-Security