Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-90
Weakness type CWE-90 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 36 | 36 | 0 |
Monthly trend
▂▁▁▂▃▄▅▅█▁
2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 5 · 2026-07 7 · 2026-08 7 · 2026-09 12 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-42568 | 4.3 | 61.8 | — | Yamcs Vulnerable to LDAP Injection in LdapAuthModule |
| CVE-2026-46619 | 9.3 | 61.3 | — | OpenAM Authentication Bypass via MSISDN LDAP Injection |
| CVE-2026-1498 | 7.0 | 59.1 | — | WatchGuard Firebox LDAP Injection |
| CVE-2026-47303 | 8.8 | 56.4 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-44617 | 6.5 | 56.3 | — | Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867 |
| CVE-2026-58222 | 8.8 | 55.2 | — | Samba: samba ad ldap compare filter injection and trusted-request confusion disclose pr… |
| CVE-2026-44616 | 6.5 | 53.6 | — | Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction |
| CVE-2026-46745 | 5.3 | 53.6 | — | Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap rea… |
| CVE-2026-49268 | 8.8 | 53.5 | — | Apache Shiro: LDAP DN Injection in DefaultLdapRealm |
| CVE-2026-11748 | 6.9 | 47.8 | — | — |
| CVE-2026-75020 | 7.0 | 43.8 | — | Apache APISIX: ldap-auth plugin cross-subtree identity impersonation |
| CVE-2026-11770 | 7.5 | 42.6 | — | 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check |
| CVE-2026-0636 | 5.5 | 42.7 | — | LDAP Injection Vulnerability in LDAPStoreHelper.java |
| CVE-2026-55770 | 6.8 | 42.5 | — | OpenBao: LDAPi ldaputil (wrong escape func) |
| CVE-2026-13696 | 8.8 | 42.0 | — | LDAP Injection in HAVELSAN's Liman MYS |
| CVE-2026-44930 | 9.8 | 41.2 | — | Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository |
| CVE-2026-41573 | 7.1 | 40.4 | — | OpenAM LDAP Injection via `_queryId` Parameter |
| CVE-2026-53658 | 6.3 | 36.9 | — | Fabric CA: LDAP Injection via Unescaped Username in GetUser Filter |
| CVE-2026-19930 | 2.1 | 34.4 | — | Dolibarr User Cloning card.php ldap injection |
| CVE-2026-45559 | 4.9 | 31.6 | — | Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only) |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 8 |
| red hat | 4 |
| legion of the bouncy castle | 2 |
| openidentityplatform | 2 |
| dell | 1 |
| drupal | 1 |
| eleveo | 1 |
| glpi-project | 1 |
| havelsan | 1 |
| hyperledger | 1 |
| jenkins project | 1 |
| ly | 1 |
| microsoft | 1 |
| netatalk | 1 |
| okta | 1 |