Unrated severityNVD Advisory· Published Feb 7, 2026· Updated Mar 5, 2026
WeKan < 8.19 LDAP Authentication Filter Injection
CVE-2026-25560
Description
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/wekan/wekan/commit/0b0e16c3eae28bbf453d33a81a9c58ce7db6d5bbmitrepatch
- www.vulncheck.com/advisories/wekan-ldap-authentication-filter-injectionmitrethird-party-advisory
- wekan.fimitreproduct
News mentions
0No linked articles in our index yet.