← Vulnerability feed

Vulnerability record · CVE-2026-44930 · published 22 May 2026

CVE-2026-44930: Apache cxf ldap injection vulnerability

Apache · Cxf

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

9.8 CVSS 3.1 Critical EPSS 0.51% · top 59.1% CWE-90 · LDAP injection
9.8CVSS 3.1 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
23 Jul 2026Last modified by NVD

Description

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-44930 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2379Apache cxf vulnerabilityApache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 pol…EPSS 4.1%9.8CVE-2026-68079Apache cxf authentication bypass by capture-replay vulnerabilityIn Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…EPSS 0.68%9.8CVE-2026-66909Apache cxf deserialization of untrusted data vulnerabilityApache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…EPSS 1.1%9.8CVE-2026-49875Apache cxf xml external entity (xxe) vulnerabilityApache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…EPSS 0.81%9.8CVE-2026-50628Apache cxf improper input validation vulnerabilityA logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…EPSS 1.0%9.8CVE-2025-48913Apache cxf improper input validation vulnerabilityIf untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…EPSS 0.82%9.8CVE-2022-46364Apache cxf server-side request forgery (ssrf) vulnerabilityA SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…EPSS 2.2%9.8CVE-2019-12419Apache cxf incorrect authorization vulnerabilityApache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2026-44930), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.