7.4
CVE-2026-13608
- EPSS 0.27%
- Veröffentlicht 06.09.2026 17:47:01
- Zuletzt bearbeitet 15.09.2026 07:16:26
- Erkennungen
OpenLDAP SASL authentication bypass
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.183 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-923 Improper Restriction of Communication Channel to Intended Endpoints
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://curl.se/docs/CVE-2026-13608.json
https://curl.se/docs/CVE-2026-13608.html
https://hackerone.com/reports/3822248