Vulnerability record · CVE-2020-26542 · published 9 November 2020
CVE-2020-26542: Percona server improper authentication vulnerability
Percona · Percona Server
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deployed at the level granted to the authenticating account.
Description
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deployed at the level granted to the authenticating account.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jira.percona.com/browse/PS-7358 | Issue TrackingPermissions RequiredVendor Advisory |
| https://jira.percona.com/browse/PSMDB-726 | Issue TrackingPermissions RequiredVendor Advisory |
| https://www.percona.com/blog/2020/10/13/percona-distribution-for-mysql-pxc-variant-8-0-20-fixes-for-security-vulnerabili | Release NotesVendor Advisory |
| https://www.percona.com/doc/percona-distribution-mysql/8.0/release-notes-pxc-v8.0.20.upd2.html | Release NotesVendor Advisory |
| https://jira.percona.com/browse/PS-7358 | Issue TrackingPermissions RequiredVendor Advisory |
| https://jira.percona.com/browse/PSMDB-726 | Issue TrackingPermissions RequiredVendor Advisory |
| https://www.percona.com/blog/2020/10/13/percona-distribution-for-mysql-pxc-variant-8-0-20-fixes-for-security-vulnerabili | Release NotesVendor Advisory |
| https://www.percona.com/doc/percona-distribution-mysql/8.0/release-notes-pxc-v8.0.20.upd2.html | Release NotesVendor Advisory |
Track CVE-2020-26542 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-26542), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.