CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX.
A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach.
This issue affects Apache APISIX: from 2.11.0 through 3.17.0.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.18.0Patch CVE-2026-75020
Event History
Frequently Asked Questions
Who is exposed to this issue?
Apache APISIX deployments using the ldap-auth plugin are affected if they run versions from 2.11.0 through 3.17.0. The issue concerns LDAP directory configurations where the plugin’s configured scope is intended to restrict which entries can be used for consumer mapping.
What does an attacker need to exploit it?
An attacker needs valid credentials for an LDAP directory entry. Those credentials can then be used to authenticate through APISIX as a consumer mapped to a different LDAP entry outside the intended configured scope.
How should affected deployments be remediated?
Upgrade Apache APISIX to version 3.18.0, which fixes the issue.