7.4
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password.
Affected versions:
Spring LDAP 2.4.0 through 2.4.4; 3.2.0 through 3.2.17; 3.3.0 through 3.3.7; 4.0.0 through 4.0.3.
Affected versions:
Spring LDAP 2.4.0 through 2.4.4; 3.2.0 through 3.2.17; 3.3.0 through 3.3.7; 4.0.0 through 4.0.3.
Basic Information
ID
CVE-2026-41720
Source
vmware
Published
Jun 9, 2026 at 03:48
Affected Product
Vendor
Spring
Product
Spring LDAP
Version
2.4.0
Affected Versions
Spring Spring LDAP 2.4.0
Spring Spring LDAP 3.2.0
Spring Spring LDAP 3.3.0
Spring Spring LDAP 4.0.0
Spring Spring LDAP 3.2.0
Spring Spring LDAP 3.3.0
Spring Spring LDAP 4.0.0