CVE-2026-102156: Security Advisory 0191
Published Oct 6, 2026
·Updated
Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high-complexity conditions, to inject queries against the configured directory service.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.2.1Patch Security Advisory 0191
Event History
Oct 6, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness