Home
MEDIUM: 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
2.1.0 (semver)
affected
4.5.0 (semver)
unaffected
Description
An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDAP queries and obtain limited information or modify LDAP entries via crafted filter input.
Problem types
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
Product status
2.1.0 (semver)
4.5.0 (semver)
Credits
Arjun Basnet from Securin
References
netatalk.io/security/CVE-2026-44063 (Netatalk Security Advisory CVE-2026-44063)