CVE-2026-10549: Privilege escalation in Yandex Database
LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Yandex Databaseto a version that resolves this vulnerability.Fixed in 25.3.1.25
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10549?
The severity of CVE-2026-10549 is classified as medium with a CVSS score of 5.3.
How do I fix CVE-2026-10549?
To mitigate CVE-2026-10549, upgrade Yandex Database to version 25.3.1.25 or later.
What types of attacks does CVE-2026-10549 enable?
CVE-2026-10549 enables privilege escalation attacks through LDAP filter injection.
Who is affected by CVE-2026-10549?
CVE-2026-10549 affects users of Yandex Database versions prior to 25.3.1.25.
What are the potential consequences of CVE-2026-10549?
The potential consequences of CVE-2026-10549 include unauthorized access to the database due to bypassing group membership checks.