CVE-2026-23906Patch(apache / druid)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache druid systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind                                                                                                                                                    Vulnerability Description An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow anonymous binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to otherwise restricted Druid resources without valid credentials. The vulnerability stems from improper validation of LDAP authentication responses when anonymous binds are permitted, effectively treating anonymous bind success as valid user authentication. Impact A remote, unauthenticated attacker can: * Gain unauthorized access to the Apache Druid cluster * Access sensitive data stored in Druid datasources * Execute queries and potentially manipulate data * Access administrative interfaces if the bypassed account has elevated privileges * Completely compromise the confidentiality, integrity, and availability of the Druid deployment                                                                                                                                                                                     Mitigation   Immediate Mitigation (No Druid Upgrade Required):                                                                                                                                                   * Disable anonymous bind on your LDAP server. This prevents the vulnerability from being exploitable and is the recommended immediate action. Resolution * Upgrade Apache Druid to version 36.0.0 or later, which includes fixes to properly reject anonymous LDAP bind attempts.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • druid

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-09); latest day: 2
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
druid

Deep dive

Activity timeline9 mentions / 5d
01122Mentions · 2026-02-09: 2Mentions · 2026-02-10: 2Mentions · 2026-02-11: 2Mentions · 2026-02-17: 1Mentions · 2026-09-10: 2Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-09-10: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-02-11: 1Technical Details · 2026-02-17: 1Technical Details · 2026-09-10: 102-0902-1002-1102-1709-10
Signal classification3 categories
Patch
444.4%
Disclosure
333.3%
General
222.2%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-092
General1Patch1
2026-02-102
Disclosure2
2026-02-112
General1Patch1
2026-02-171
Patch1
2026-09-102
Disclosure1Patch1
Full discourse9 posts
  • Wazuh@wazuh
    Patch

    Apache Druid is affected by CVE-2026-23906, a critical authentication bypass that can allow unauthorized access when LDAP anonymous bind is enabled. Update to Druid 36.0.0+ and disable anonymous bind. Read more: https://ow.ly/uZyV50YfixF https://t.co/aXLtRbdyGr

    Post summary

    Apache Druid CVE‑2026‑23906 is a critical authentication bypass; it can be mitigated by updating to version 36.0.0+ and disabling LDAP anonymous binding.

    1701741.1K
    7.8K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-23906: Apache Druid: Authentication Bypass via LDAP Anonymous Bind https://www.openwall.com/lists/oss-security/2026/02/09/5 by providing an existing username with an empty password. Immediate Mitigation: Disable anonymous bind on your LDAP server. Resolution: Upgrade to version 36.0.0 or later.

    Post summary

    The advisory discloses an authentication bypass in Apache Druid through LDAP anonymous bind, offering technical details and recommending disabling anonymous bind and upgrading to version 36.0.0 or later.

    010731.0K
    4.4K followersView on X
  • CVE Brief@DailyCVEBrief
    Disclosure

    LOOK BACK — Apache Druid trusted an LDAP bind that did not throw an error as proof the password was right. A real username plus an empty password logged you in. CVE-2026-23906 shipped in Jan 2020 and sat there for six years. https://t.co/M3l3pe4a5n

    Post summary

    The tweet discloses that CVE-2026-23906 in Apache Druid permits authentication bypass by exploiting a silent LDAP bind, noting it remained unpatched for six years.

    1000053
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-23906 CVE-2026-23906 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23906 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The content merely cites CVE-2026-23906 and directs readers to Vulmon for additional information, providing no technical or exploitation details.

    0000138
    4.0K followersView on X
  • CVE Brief@DailyCVEBrief
    Patch

    Full Look Back: a 3-line fix that RFC 4513 prescribed back in 2006, a 9.8 that came from enrichment rather than the vendor, and no 35.x backport. https://cvebrief.com/cve/cve-2026-23906/ https://t.co/9cCpcQAbrq

    Post summary

    The tweet references CVE‑2026‑23906 and mentions a 3‑line fix from RFC 4513, but provides no PoC, exploit details, or evidence of active attacks.

    0000035
    31 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An authentication bypass vulnerability (CVE-2026-23906) affects `Apache Druid` via its `druid-basic-security` extension. Update to version 36.0.0. #ApacheDruid #InfoSec #AuthBypass https://www.pulsepatch.io/posts/cve-2026-23906-apache-druid-authentication-bypass

    Post summary

    Apache Druid CVE-2026-23906 is an authentication bypass flaw mitigated by upgrading to version 36.0.0.

    0000037
    1 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full details about CVE-2026-23906 from https://vulntracker.io/cves/CVE-2026-23906

    Post summary

    The tweet simply directs readers to a link for full details on CVE-2026-23906, without providing additional context or technical information.

    0000031
    333 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-23906: The Ghost in the LDAP: Apache Druid Authentication Bypass Apache Druid, the high-performance real-time analytics database, has dropped the ball on basic authentication logic. By failing to differentiate between an 'anonymous' LDAP bind... https://cvereports.com/reports/CVE-2026-23906

    Post summary

    The text announces a new authentication bypass in Apache Druid involving LDAP, detailing the technical flaw but providing no exploit, patch, or evidence of active use.

    0000031
    27 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-23906 - Critical Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled ... https://www.thehackerwire.com/vulnerability/CVE-2026-23906/ https://t.co/NFgZttW8RZ

    Post summary

    CVE-2026-23906 is a critical vulnerability affecting Apache Druid versions 0.17.0 to 35.x when the druid-basic-security extension is enabled, but no PoC, exploit, or patch is mentioned in the text.

    0000050
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachedruid---

Explore more