CVE-2026-81205 PUBLISHED

LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115

Assigner: drupal
Reserved: 26.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

Product Status

Vendor Drupal
Product LDAP / Active Directory Integration
Versions
  • affected from 0.0.0 to 2.2.1 (excl.)

Credits

  • Marcus Johansson (marcus_johansson) finder
  • Harshvardhan Soni (sharsh) remediation developer
  • Sudhanshu Dhage (sudhanshu0542) remediation developer
  • Swan Kalata (akalata) coordinator
  • Greg Knaddison (greggles) coordinator
  • Juraj Nemec (poker10) coordinator
  • Jess (xjm) coordinator

References

Problem Types

  • CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CWE

Impacts

  • CAPEC-136 LDAP Injection