Junglewise Threat Intelligence

CVE-2026-24130: PYSEC-2026-1679 - Moonraker affected by LDAP search filter injection

CVE-2026-24130 · Severity: medium · CVSS 4 · Published 2026-07-07

Vendors: PyPI.

Executive brief

Moonraker is a 3D printer control and monitoring application that supports LDAP authentication for user login. When LDAP is configured, attackers can exploit the login endpoint to inject crafted LDAP queries and extract sensitive directory information like user IDs and attributes by observing authentication error messages. This could allow attackers to enumerate valid accounts on an organization's LDAP server without requiring valid credentials.

Technical details

The vulnerability is a classic LDAP search filter injection (CWE-90) in Moonraker's login endpoint when LDAP authentication is enabled. Attackers can manipulate LDAP filter syntax in login requests to inject arbitrary filter conditions. The vulnerability is exploitable because error responses differ between successful and failed searches, allowing attackers to perform information disclosure attacks via blind search techniques. The vulnerability affects versions prior to 0.10.0; users can upgrade to patch the issue, or mitigate by configuring max_login_attempts in the authorization section or disabling LDAP entirely in favor of built-in authentication.

Affected products

  • Arksine Moonraker < 0.10.0

Timeline

  • 2026-01-22: disclosed
  • 2026-01-22: patched: Version 0.10.0 patches the vulnerability

References