CVE-2026-101145
Received Received - Intake

LDAP Injection in Eleveo Call Recording Software

Vulnerability report for CVE-2026-101145, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eleveo call_recording_software 9.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-90 The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an LDAP injection flaw in Eleveo Call Recording Software 9.7.0. It allows attackers to manipulate the Username argument in the /callrec/userAddAction.do file to inject malicious LDAP queries. This can lead to unauthorized data access or manipulation.

Detection Guidance

Detecting LDAP injection vulnerabilities like this one typically involves monitoring for unusual input patterns in HTTP requests to the /callrec/userAddAction.do endpoint. Check logs for suspicious Username parameter values containing LDAP filter characters like *, (, ), &, |, or =. Use tools like Burp Suite or OWASP ZAP to intercept and analyze requests for malformed input attempts.

Impact Analysis

The impact includes potential unauthorized access to sensitive data, privilege escalation, or disruption of services. Since the exploit is publicly available, attackers could remotely exploit this flaw without authentication.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing personal or health data. Unauthorized access risks violating data protection requirements, potentially resulting in legal penalties or reputational damage.

Mitigation Strategies

Immediately update Eleveo Call Recording Software to the latest version if available. If no patch exists, restrict access to the /callrec/userAddAction.do endpoint via network firewall rules. Implement input validation for the Username parameter to block LDAP special characters. Monitor network traffic for signs of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101145. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart