Executive brief
Liderahenk is an administrative management platform used by Turkish organizations. An LDAP injection vulnerability allows attackers to manipulate LDAP queries, potentially enabling unauthorized access to directory data or account information stored in LDAP directories that the system relies on for authentication and user management.
Technical details
This vulnerability is an LDAP injection flaw (improper neutralization of special elements in LDAP queries) in TÜBİTAK BİLGEM's Liderahenk platform. The vulnerability affects versions 3.4.0 through 3.5.4; it has been patched in version 3.5.5. An attacker can inject malicious LDAP syntax into user input fields to modify the structure and logic of LDAP queries executed by the application. This typically requires network access to Liderahenk and may require prior authentication depending on which input vectors are vulnerable. Successful exploitation could allow an attacker to bypass authentication, enumerate directory information, or modify LDAP operations.
Affected products
- TÜBİTAK BİLGEM Liderahenk 3.4.0 to 3.5.4
Timeline
- 2026-08-26: disclosed
- 2026: patched: Fixed in version 3.5.5