LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-35563

apache · directory ldap api

Published
CVSS8.5
Severityhigh
WeaknessCWE-297
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code validates the certificate chain against a trusted authority, the absence of endpoint identification allows a valid certificate issued for an entirely unrelated host to be improperly accepted. This oversight leaves the connection highly vulnerable to server impersonation and complete connection compromise. The root cause of this vulnerability lies in the incomplete TLS server identity verification within the LDAP client implementation. The attacker requires MITM capability on the network to exploit this vuln

References

← Back to the CVE Tracker

Our coverage of CVE-2026-35563

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-35563.