VulnerabilityModified
CVE-2026-44930
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
CRITICAL 9.8EPSS 0.69%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-90
- Affected
- apache/cxf
- Source
- security@apache.org
References
- https://lists.apache.org/thread/c1zqxppo1m5z3kbdhjn5p991zk09ynkhMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/05/22/9
- https://access.redhat.com/errata/RHSA-2026:37390
- https://access.redhat.com/security/cve/CVE-2026-44930
- https://bugzilla.redhat.com/show_bug.cgi?id=2480728
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44930.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.