Junglewise Threat Intelligence

CVE-2026-4256: PEAKUP PassGate LDAP injection

CVE-2026-4256 · Severity: high · CVSS 8.2 · Published 2026-07-09

Executive brief

PEAKUP PassGate, a solution used for identity and access management, contains a security flaw that could allow unauthorized individuals to manipulate directory queries. By exploiting this vulnerability, an attacker could potentially bypass security controls to view sensitive user information or gain unauthorized access to the system. This poses a significant risk to corporate data privacy and the integrity of the organization's authentication infrastructure.

Technical details

An LDAP injection vulnerability exists in PEAKUP Technology Inc. PassGate due to improper neutralization of special elements used in LDAP queries (CWE-90). The flaw allows a remote, unauthenticated attacker to send specially crafted input to the application, which is then improperly concatenated into an LDAP query. Successful exploitation enables the attacker to alter the logic of the query, potentially leading to the disclosure of sensitive information from the LDAP directory or bypassing authentication mechanisms. The vulnerability is present in versions through 30042026 and can be exploited over the network without user interaction.

Affected products

  • PEAKUP Technology Inc. PassGate through 30042026

Timeline

  • 2026-07-09: advisory: Published by NVD and TR-CERT

References