Junglewise Threat Intelligence

CVE-2026-44930: Apache CXF LDAP injection in XKMS LDAP Certificate repository

CVE-2026-44930 · Severity: critical · CVSS 9.8 · Published 2026-05-22

Technologies: Apache Software Foundation CXF. Vendors: Apache Software Foundation.

Executive brief

Apache CXF is a popular open-source framework used to build and develop web services. A security flaw in its certificate management component allows an attacker to manipulate database queries to retrieve sensitive digital certificates they should not have access to. This could lead to the exposure of private security credentials and unauthorized access to protected systems.

Technical details

An LDAP injection vulnerability (CWE-90) exists in the LDAP Certificate repository of the XKMS (XML Key Management Specification) server component within Apache CXF. The flaw is located in the 'cxf-services-xkms-x509-repo-ldap' package, where improper neutralization of special elements in LDAP queries allows an attacker to influence the query logic. A remote, unauthenticated attacker can exploit this by sending crafted requests to the XKMS server to bypass intended filters and retrieve arbitrary X.509 certificates from the backend repository. This issue is resolved in versions 3.6.11, 4.1.6, and 4.2.1.

Affected products

  • Apache Software Foundation Apache CXF < 3.6.11, 4.0.0 to < 4.1.6, 4.2.0 to < 4.2.1

Timeline

  • 2026-05-22: disclosed: Initial disclosure by Apache Software Foundation
  • 2026-05-22: advisory: NVD and Openwall advisories published
  • 2026-06-17: other: CISA-ADP enrichment and Red Hat tracking updated

References

Related threats