CVE-2026-44930Disclosure(apache / cxf)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache cxf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cxf

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 1 mentions (2026-05-22); latest day: 1
  • 7 total mentions across 7 days

Affected systems

Vendors
Products
cxf

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 7d
00111Mentions · 2026-05-22: 1Mentions · 2026-05-23: 1Mentions · 2026-05-26: 1Mentions · 2026-05-28: 1Mentions · 2026-05-29: 1Mentions · 2026-06-02: 1Mentions · 2026-07-20: 1Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-02: 1Technical Details · 2026-07-20: 105-2205-2305-2605-2805-2906-0207-20
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-221
General1
2026-05-231
Disclosure1
2026-05-261
Disclosure1
2026-05-281
Disclosure1
2026-05-291
Patch1
2026-06-021
Disclosure1
2026-07-201
Patch1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache CXF CVE-2026-44417: Incomplete fix for CVE-2025-48913 Untrusted JMS configuration can lead to RCE https://www.openwall.com/lists/oss-security/2026/05/22/7 CVE-2026-44618: XXE in WS-Transfer functionality https://www.openwall.com/lists/oss-security/2026/05/22/8 CVE-2026-44930: LDAP Injection in XKMS LDAP Repository https://www.openwall.com/lists/oss-security/2026/05/22/9

    Post summary

    The post lists three new Apache CXF CVEs, detailing their vulnerability types (RCE, XXE, LDAP injection) and provides links to discussion threads, with no evidence of exploitation or mitigation.

    010511.2K
    4.7K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    CVE-2026-44930: Critical (9.8) LDAP injection in Apache CXF's XKMS server. No auth needed - attackers can retrieve arbitrary certificates from the LDAP repository. If you run Apache CXF with XKMS, update now. #apachecxf #infosec https://secalerts.co/vulnerability/CVE-2026-44930 https://t.co/flCRexrdJ9

    Post summary

    The tweet alerts users to a critical LDAP injection flaw in Apache CXF XKMS that allows unauthenticated retrieval of certificates, and urges immediate update.

    00010139
    826 followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ NetApp Active IQ Unified Manager for Linux alert: CVE-2026-44930 (CVSS 9.8) Attackers could disrupt service or cause a denial of service. No workaround is available; follow the vendor advisory for updates. https://vulnipulse.com/advisories/netapp-ntap-20260618-0001 #NetApp #CyberSecurity #CVE

    Post summary

    The tweet announces CVE‑2026‑44930 for NetApp Active IQ Unified Manager, highlights its high CVSS score and denial‑of‑service impact, and urges users to monitor the vendor advisory as no workaround exists.

    0000045
    6 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache CXF の脆弱性 CVE-2026-44930 がFIX:LDAP インジェクションと不正アクセス https://iototsecnews.jp/2026/05/26/apache-cxf-flaw-exposes-systems-to-ldap-injection-attacks/ Apache CXF の脆弱性 CVE-2026-44930 は、外部からの正しく検証されていない入力値が、LDAP クエリに組み込まれてしまうことに起因します。ユーザーの入力した文字列を、システムが信じて処理してしまうと、クエリの構造が攻撃者により書き換えられてしまいます。その結果、本来は到達できない証明書データの外部への漏洩や、認証の回避といったリスクが生じます。このように、外部との接点におけるサニタイズ不足は、重大なセキュリティ・インシデントに直結することがあります。ご利用のチームは、ご注意ください。 #Apache #CVE202644930 #CXF #Vulnerability

    Post summary

    The article reports a new LDAP injection flaw in Apache CXF (CVE‑2026‑44930), detailing how unsanitized user input can be used to alter LDAP queries, causing sensitive data exposure and authentication bypass, but it does not mention PoC code, exploits, active attacks, or patches.

    0000062
    491 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Apache CXFのXKMS LDAPサービスにLDAPインジェクションが可能になる脆弱性 CVE-2026-44930 https://rocket-boys.co.jp/security-measures-lab/apache-cxf-xkms-ldap-injection-cve-2026-44930/ #セキュリティ対策Lab #security #securitynews

    Post summary

    A new vulnerability, CVE‑2026‑44930, has been disclosed that allows LDAP injection in Apache CXF’s XKMS LDAP service, as announced on a security blog.

    00000120
    407 followersView on X
  • Israel@f1tym1
    Disclosure

    Apache CXF LDAP Injection Vulnerability Let Attacker Retrieve Arbitrary Certificates https://ift.tt/lguEIKw A newly disclosed vulnerability in Apache CXF, tracked as CVE-2026-44930, is raising concerns among enterprise users relying on its XKMS (XML Key Management Specificati…

    Post summary

    A newly disclosed Apache CXF LDAP injection flaw (CVE-2026-44930) enables attackers to access arbitrary certificates through the XKMS interface.

    0000045
    980 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-44930 CVE-2026-44930 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44930 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post simply advertises CVE‑2026‑44930 and points to a vulnerability detail page and an alerts page, but provides no technical, exploit, or patch information.

    0000070
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecxf---
Appapachecxf4.2.0--

Explore more