THREATOPS
THREAT OPSThreat News › CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation

CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation

medoss_secPublished 2026-08-26

<p>Posted by Abhishek Choudhary on Aug 26</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache APISIX 2.11.0 through 3.17.0<br /> <br /> Description:<br /> <br /> Improper Neutralization of Special Elements used in an LDAP Query (&apos;LDAP Injection&apos;) vulnerability in Apache APISIX.<br /> <br /> A caller who holds valid credentials for one entry in the LDAP directory can authe

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/592