← All Advisories

CVE-2026-103878

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-103878

Key Details

CVECVE-2026-103878
Affected productsApache Software Foundation Apache Directory LDAP API
Classified asCWE-345 (Insufficient Verification of Data Authenticity)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apache Software FoundationApache Directory LDAP API
SubsystemsGeneral OT
SectorsMultiple

What to Know

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API.

A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed.

This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.

Users are recommended to upgrade to version 2.1.9, which fixes the issue. (NVD)

What to Do

Monitor Apache Software Foundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-103878
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-103878