Vulnerability Description
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.
Related Weaknesses (CWE)
References
- https://github.com/line/centraldogma/security/advisories/GHSA-98q5-5qh2-7w75
- https://github.com/line/centraldogma/security/advisories/GHSA-98q5-5qh2-7w75
FAQ
What is CVE-2026-11748?
CVE-2026-11748 is a documented vulnerability. A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter with...
How severe is CVE-2026-11748?
CVSS scoring is not yet available for CVE-2026-11748. Check NVD for updates.
Is there a patch for CVE-2026-11748?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.