CVE-2026-103877: Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API.
A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE.
This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.
Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Directory LDAP APIto a version that resolves this vulnerability.Fixed in 2.1.9
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Clients using Apache Directory LDAP API versions 2.1.0 through before 2.1.9 are affected when they call loadSchema() against an LDAP server whose responses cannot be trusted. This includes connections to a rogue or compromised LDAP server and connections vulnerable to a pre-TLS man-in-the-middle attacker.
What must an attacker be able to do to exploit it?
The attacker must be able to control or alter the LDAP server response to the client's loadSchema() subschema search. The malicious schema object must contain a serialized Java class.
What is the recommended remediation?
Upgrade Apache Directory LDAP API to version 2.1.9, which fixes the issue.