https://seclists.org/oss-sec/2026/q3/961: CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules
Published Sep 28, 2026
·Updated
Affected Software
1 affected component
Apache Karaf<4.4.12
Frequently Asked Questions
1
Which deployments are affected?
Apache Karaf deployments using the org.apache.karaf.jaas.modules.ldap LDAP login modules are affected if they run a version before 4.4.12. The affected code paths are LDAPCache and LDAPBackingEngine.
2
What does an attacker need to exploit this issue?
An attacker needs to supply a login name containing LDAP filter-special characters such as *, (, ), or NUL. Exploitation depends on administrator-configured userFilter or roleFilter templates that substitute %u, %dn, or %fqdn into LDAP search filters.
3
What is the likely security impact?
The crafted value can alter the LDAP filter structure, causing user or role lookups to return an entry other than the intended one. This can widen matches and potentially over-grant roles.
4
What version should be used to remediate the issue?
Upgrade Apache Karaf to version 4.4.12 or later. The affected versions are those before 4.4.12.