SA-CONTRIB-2026-115: Critical severity drupal/ldap_auth vulnerability
Published Aug 26, 2026
·Updated
This module enables users to authenticate using LDAP or Active Directory credentials. The module does not sufficiently sanitize user-supplied input before incorporating it into an LDAP search filter. This allows an attacker to discover additional information they should not normally be able to.
Credit
Marcus Johansson (marcus_johansson)
Affected Software
1 affected componentFixes available
drupal/ldap_auth<2.2.1
2.2.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/ldap_authto a version that resolves this vulnerability.Fixed in 2.2.1
Event History
Aug 26, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Are affected or fixed versions identified?
No affected or fixed versions are provided in the available data for drupal/ldap_auth.
2
Has the advisory been updated since publication?
The advisory was published and last modified on 2026-08-26.