Executive brief
Yandex Database (YDB) is an open-source distributed SQL database. A security flaw in how the database handles identity lookups allows users with valid login credentials to bypass security group restrictions. This could allow an attacker to access sensitive data or perform actions they are not authorized to do within the database environment.
Technical details
An LDAP filter injection vulnerability exists in Yandex Database (YDB) versions prior to 25.3.1.25. The flaw resides in the handling of LDAP queries used for authorization, where insufficient sanitization allows an attacker to manipulate the LDAP filter logic. A remote attacker with valid LDAP credentials can exploit this to bypass group membership verification, effectively escalating their privileges or gaining unauthorized access to database resources. The vulnerability is addressed in version 25.3.1.25.
Affected products
- Yandex Yandex Database (YDB) prior to 25.3.1.25
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory