<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aapachecxf/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 26 May 2026 13:52:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aapachecxf/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-44930: Apache CXF LDAP Injection Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-05-apache-cxf-ldap-injection/</link><pubDate>Tue, 26 May 2026 13:52:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-apache-cxf-ldap-injection/</guid><description>CVE-2026-44930 is an LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF that may allow an attacker to retrieve arbitrary certificates from the repository.</description><content:encoded><![CDATA[<p>An LDAP injection vulnerability exists within the LDAP Certificate repository of the XKMS server in Apache CXF. This flaw, identified as CVE-2026-44930, potentially allows a remote attacker to inject malicious LDAP queries. Successful exploitation could lead to the unauthorized retrieval of arbitrary certificates from the repository. The vulnerability affects Apache CXF versions prior to 4.2.1, 4.1.6, and 3.6.11. Organizations using Apache CXF should upgrade to the patched versions to mitigate this risk.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies an Apache CXF server with an exposed XKMS service using the LDAP Certificate repository.</li>
<li>The attacker crafts a malicious LDAP query string containing injection payloads.</li>
<li>The attacker sends a request to the vulnerable XKMS endpoint, embedding the malicious LDAP query.</li>
<li>The Apache CXF server processes the request and constructs an LDAP query using the attacker-supplied input without proper sanitization.</li>
<li>The crafted LDAP query is executed against the LDAP server.</li>
<li>Due to the LDAP injection vulnerability, the attacker is able to bypass intended access controls.</li>
<li>The attacker retrieves sensitive certificate data from the LDAP server that they are not authorized to access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-44930 can lead to the unauthorized disclosure of sensitive information, specifically the arbitrary certificates stored within the LDAP repository. The impact of this vulnerability is significant as compromised certificates can be used for identity spoofing, man-in-the-middle attacks, and other malicious activities. Organizations utilizing affected versions of Apache CXF are at risk of having their certificate data exposed.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to Apache CXF versions 4.2.1, 4.1.6, or 3.6.11 to remediate the LDAP injection vulnerability as advised in the advisory (<a href="https://lists.apache.org/thread/c1zqxppo1m5z3kbdhjn5p991zk09ynkh">https://lists.apache.org/thread/c1zqxppo1m5z3kbdhjn5p991zk09ynkh</a>).</li>
<li>Deploy the Sigma rule &ldquo;Detects CVE-2026-44930 Exploitation — Malicious LDAP Query&rdquo; to identify potential exploitation attempts.</li>
<li>Monitor web server logs for unusual LDAP-related requests targeting the XKMS service.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ldap-injection</category><category>cve</category><category>web-application</category></item></channel></rss>