CVE-2026-11748
Received
Received - Intake
Authentication Bypass via LDAP Filter Injection in CentralDogma
Publication date: 2026-06-22
Last updated on: 2026-06-22
Assigner: LINE Corporation
Description
Description
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| line | centraldogma-server-auth-shiro | to 0.84.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |