Skip to content
COOEY

EXPOSURES › CVE-2026-44930

CVE-2026-44930

CRITICAL
DETAIL
SourceNVD · cve Published2026-05-22 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-44930 ↗
SHAME 35/100

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.