Medium severityNVD Advisory· Published Jun 22, 2026· Updated Jun 22, 2026
CVE-2026-11748
CVE-2026-11748
Description
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.84.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.