Intel

AIKIDO-2026-125234

drupal/ldap_auth is vulnerable to LDAP Injection

LDAP InjectionCVE-2026-81205 Published Yesterday

50

Medium Risk

This Affects:

PHPdrupal/ldap_auth
0.0.1 - 2.2.0
Fixed in 2.2.1
Are you affected? Scan for Free

TL;DR

An LDAP injection vulnerability in the module allows attackers to manipulate LDAP search filters through insufficiently sanitized user input, potentially exposing information they should not have access to.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/ldap_auth is vulnerable to LDAP Injection in versions 0.0.1 - 2.2.0.

How to fix this

Upgrade the drupal/ldap_auth library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform