CVE-2026-19271: Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
Published Aug 26, 2026
·Updated
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection.
This issue affects Liderahenk: from 3.4.0 before 3.5.5.
Affected Software
1 affected component
TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk>=3.4.0<3.5.5
Event History
Aug 26, 2026
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Liderahenk deployments are affected?
Liderahenk versions from 3.4.0 up to, but not including, 3.5.5 are affected.
2
Does exploitation require authentication or user interaction?
No. The supplied vector indicates the issue is remotely exploitable over the network with low attack complexity, requires no privileges, and requires no user interaction.
3
What security impact can this issue have?
The provided severity vector indicates high confidentiality impact. It does not indicate integrity or availability impact.