THREAT OPS › Threat News › CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
<p>Posted by Abhishek Choudhary on Aug 26</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache APISIX 2.11.0 through 3.17.0<br /> <br /> Description:<br /> <br /> Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX.<br /> <br /> A caller who holds valid credentials for one entry in the LDAP directory can authe
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-75020cve
Original source: https://seclists.org/oss-sec/2026/q3/592