https://seclists.org/oss-sec/2026/q1/154: CVE-2026-23906: Apache Druid: Authentication Bypass via LDAP Anonymous Bind
Published Feb 9, 2026
·Updated
Affected Software
2 affected components
Apache Druid<36.0.0
maven/org.apache.druid/extensions/druid-basic-security>=0.17.0<36.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-23906?
CVE-2026-23906 has been classified as important.
2
Which versions of Apache Druid are affected by CVE-2026-23906?
CVE-2026-23906 affects Apache Druid versions 0.17.0 through 35.x, all versions prior to 36.0.0.
3
How does CVE-2026-23906 impact system security?
CVE-2026-23906 allows for authentication bypass via LDAP Anonymous Bind, which can compromise system security.
4
How can I mitigate CVE-2026-23906 in my environment?
To mitigate CVE-2026-23906, upgrade Apache Druid to version 36.0.0 or later.
5
What is the nature of the vulnerability described in CVE-2026-23906?
CVE-2026-23906 is an authentication bypass vulnerability related to LDAP Anonymous Bind.