PT-2026-7140 · Apache · Druid-Basic-Security+1
Karan Kumar
·
Published
2026-02-09
·
Updated
2026-02-17
·
CVE-2026-23906
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Druid versions 0.17.0 through 35.x
Description
An authentication bypass issue exists in Apache Druid when the druid-basic-security extension is enabled with LDAP authentication. If the underlying LDAP server allows anonymous binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to Druid resources without valid credentials. The issue arises from improper validation of LDAP authentication responses when anonymous binds are permitted, treating anonymous bind success as valid user authentication. A remote, unauthenticated attacker can gain unauthorized access to the Druid cluster, access sensitive data, execute queries, potentially manipulate data, access administrative interfaces, and compromise the confidentiality, integrity, and availability of the deployment.
Recommendations
Versions 0.17.0 through 35.x: Disable anonymous bind on your LDAP server.
Versions 0.17.0 through 35.x: Upgrade to version 36.0.0 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Druid
Druid-Basic-Security