CVE-2026-103877
Received Received - Intake

Deserialization of Untrusted Data in Apache Directory LDAP API

Vulnerability report for CVE-2026-103877, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Apache Software Foundation

Description

Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE.Β  This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache directory_ldap_api From 2.1.0 (inc) to 2.1.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a deserialization of untrusted data issue in the Apache Directory LDAP API. A compromised or malicious LDAP server could send a specially crafted schema object containing a serialized Java class during a loadSchema() subschema search. This could potentially lead to remote code execution (RCE) on the client system, especially if the communication occurs before TLS encryption is established.

Detection Guidance

This vulnerability involves deserialization of untrusted data in Apache Directory LDAP API versions before 2.1.9. Detection requires checking the installed version of the library. Use commands like 'mvn dependency:tree' for Maven projects or inspect the JAR file's version metadata.

Impact Analysis

If you use the affected Apache Directory LDAP API versions (2.1.0 to 2.1.8), a rogue LDAP server could exploit this flaw to execute arbitrary code on your system. This risk is higher if the LDAP connection is not encrypted with TLS, as an attacker could intercept and manipulate the data before encryption.

Mitigation Strategies

Upgrade Apache Directory LDAP API to version 2.1.9 or later immediately. This fixes the deserialization flaw. If upgrading is not possible, consider disabling the loadSchema() functionality or restricting LDAP server connections to trusted sources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103877. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart