Логотип exploitDog
bind:CVE-2026-23906
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-23906

Количество 3

Количество 3

nvd логотип

CVE-2026-23906

около 2 месяцев назад

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind                                                                                                                                                    Vulnerability Description An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow anonymous binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to otherwise restricted Druid resources without valid credentials. The vulnerability stems from improper validation of LDAP authentication r

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-23906

около 2 месяцев назад

Affected Products and Versions * Apache Druid * Affected Version ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-q672-hfc7-g833

около 2 месяцев назад

Apache Druid Vulnerable to Authentication Bypass

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-23906

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind                                                                                                                                                    Vulnerability Description An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow anonymous binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to otherwise restricted Druid resources without valid credentials. The vulnerability stems from improper validation of LDAP authentication r

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-23906

Affected Products and Versions * Apache Druid * Affected Version ...

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-q672-hfc7-g833

Apache Druid Vulnerable to Authentication Bypass

0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу