Apache OFBiz LDAP Injection Vulnerability before 24.09.06
CVE-2026-41919 Published on May 19, 2026

Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor Advisory NVD

Weakness Type

What is a LDAP Injection Vulnerability?

The software constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

CVE-2026-41919 has been classified to as a LDAP Injection vulnerability or weakness.


Products Associated with CVE-2026-41919

Want to know whenever a new CVE is published for Apache OFBiz? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache OFBiz: