CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-44930 — An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s...
·Source: NIST NVD
Updated:
Executive Summary
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Analysis
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue. CVSS Score: 9.8. Published: 2026-05-22T13:16:22.820.