Skip to content
Rota Nacional

Cyber ·

CVE-2026-90979: LDAP injection flaw in Apache Karaf

A notice published on September 28, 2026 reports LDAP filter injection in Apache Karaf JAAS LDAP modules. Versions before 4.4.12 are affected; the notice rates severity as moderate.

A security notice published on September 28, 2026 describes CVE-2026-90979 in Apache Karaf JAAS LDAP modules. Versions before 4.4.12 are affected, and the notice rates severity as moderate.

According to the text, LDAPCache and LDAPBackingEngine build LDAP search filters to locate users and roles. Login values, the resolved user DN, and the fully qualified name are inserted by textual substitution of the %u, %dn, and %fqdn markers in administrator-configured templates such as userFilter and roleFilter, without adequate protection.

If your organization uses an affected version, check the installed version and plan an upgrade to 4.4.12 or later. Also review configured LDAP filters and consult the original notice on the oss-sec mailing list and Apache Karaf's official notes to confirm the scope and guidance for your environment.

When studying or applying this material with AI, do not submit credentials, user data, or internal configuration without authorization. Prefer fictional examples or remove identifiers; verify technical recommendations against official documentation and test changes in a controlled environment.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free