CVE-2026-81205: LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115
Published Sep 2, 2026
·Updated
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
Affected Software
4 affected components
Drupal LDAP / Active Directory Integration>=0.0.0<=2.2.1
miniOrange Ldap \/ Active Directory Integration Drupal>=2.0.1<2.2.1
miniOrange Ldap \/ Active Directory Integration Drupal>=7.x-1.0<=7.x-1.21
miniOrange Ldap \/ Active Directory Integration Drupal>=8.x-1.0<=8.x-1.34
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal LDAP / Active Directory Integrationto a version that resolves this vulnerability.Fixed in 2.2.1Patch SA-CONTRIB-2026-115
Event History
Sep 2, 2026
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which installations are affected?
Drupal LDAP / Active Directory Integration versions from 0.0.0 through 2.2.1 are affected.
2
What vulnerability class is involved?
The issue is LDAP injection caused by improper neutralization of special elements used in an LDAP query. It can result in information disclosure.