← All CVEs

CVE-2026-44930

critical · 9.8

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

9.8
CVSS
0.7%
EPSS (exploit prob.)
51st
EPSS percentile
2026-05-22
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-90

Affected products

VendorProductAffected versions
apachecxf< 3.6.11
apachecxf>= 4.0.0, < 4.1.6
apachecxf4.2.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-44930