CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8745

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules

Apache Karaf before version 4.4.12 contains a moderate-severity LDAP filter injection vulnerability in its JAAS LDAP login modules. The flaw arises from unsafe textual substitution of user-supplied login credentials into administrator-configured filter templates during user and role lookups.

Why it matters: Organizations running Karaf deployments with LDAP authentication are at risk of authentication bypass or unauthorized role elevation if they use untrusted or user-controlled input in filter templates; patching to 4.4.12 or later is the remediation path.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary