CVE-2026-90979 | Apache Karaf up to 4.4.11 LDAP Authentication Util.doRFC2254Encoding user/principal input validation

SecurityVulns

A vulnerability, which was classified as critical, was found in Apache Karaf up to 4.4.11. Affected is the function Util.doRFC2254Encoding of the component LDAP Authentication. Such manipulation of the argument user/principal leads to improper input validation.

This vulnerability is traded as CVE-2026-90979. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More