<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:12:08 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15354</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15354</link>
      <description>bdu:2026-15354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15354</guid>
    </item>
    <item>
      <title>BIT-openbao-2026-55770 — OpenBao: LDAPi ldaputil (wrong escape func)</title>
      <link>https://cve.radiocsirt.org/vuln/bit-openbao-2026-55770</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: openbao&lt;/p&gt;
&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: openbao&lt;/p&gt;
&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-openbao-2026-55770</guid>
    </item>
    <item>
      <title>EUVD-2026-370186</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-370186</link>
      <description>EUVD-2026-370186</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-370186</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55770</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55770</link>
      <description>&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55770</guid>
    </item>
    <item>
      <title>GHSA-6mwx-4547-5vc9 — OpenBao: LDAPi ldaputil (wrong escape func)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6mwx-4547-5vc9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openbao/openbao&lt;/p&gt;
&lt;p&gt;## 1. Description&lt;/p&gt;
&lt;p&gt;### Component&lt;/p&gt;
&lt;p&gt;`sdk/helper/ldaputil/client.go` — the shared LDAP utility library used by both the LDAP authentication backend and OpenLDAP secrets engine to construct LDAP search filters and bind DNs.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The LDAP utility contains a **function selection error** that causes incorrect escaping of user-controlled input in LDAP filter construction. Two lines construct the `bindDN` using `EscapeLDAPValue()`:&lt;/p&gt;
&lt;p&gt;```go
// Line 191 — UPN Domain path
bindDN = fmt.Sprintf(&amp;#34;%s@%s&amp;#34;, EscapeLDAPValue(username), cfg.UPNDomain)&lt;/p&gt;
&lt;p&gt;// Line 193 — User DN path
bindDN = fmt.Sprintf(&amp;#34;%s=%s,%s&amp;#34;, cfg.UserAttr, EscapeLDAPValue(username), cfg.UserDN)
```&lt;/p&gt;
&lt;p&gt;The problem: `EscapeLDAPValue()` implements **RFC 4514** escaping, which is designed for Distinguished Name (DN) components. It only escapes characters meaningful in DNs: `+`, `,`, `;`, `&amp;#34;`, `\`, `&amp;lt;`, `&amp;gt;`, and leading/trailing spaces.&lt;/p&gt;
&lt;p&gt;LDAP **search filters** (RFC 4515) have a different set of special characters: `*`, `(`, `)`, `\`, and NUL (`\x00`). None of these are escaped by `EscapeLDAPValue()`. The correct function is `ldap.EscapeFilter()` from the `github.com/go-ldap/ldap/v3` package.&lt;/p&gt;
&lt;p&gt;The irony: the same file uses `ldap.EscapeFilter()` correctly at lines 225-226 in `RenderUserSearchFilter()` for the `UserFilter` template path, but the `GetUserDN()` function at lines 191-193 uses the wrong escape function.&lt;/p&gt;
&lt;p&gt;### Exploitation Mechanics&lt;/p&gt;
&lt;p&gt;```
Username: alice)(objectClass=*
↓ EscapeLDAPValue (no-op — no DN special chars…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openbao/openbao&lt;/p&gt;
&lt;p&gt;## 1. Description&lt;/p&gt;
&lt;p&gt;### Component&lt;/p&gt;
&lt;p&gt;`sdk/helper/ldaputil/client.go` — the shared LDAP utility library used by both the LDAP authentication backend and OpenLDAP secrets engine to construct LDAP search filters and bind DNs.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The LDAP utility contains a **function selection error** that causes incorrect escaping of user-controlled input in LDAP filter construction. Two lines construct the `bindDN` using `EscapeLDAPValue()`:&lt;/p&gt;
&lt;p&gt;```go
// Line 191 — UPN Domain path
bindDN = fmt.Sprintf(&amp;#34;%s@%s&amp;#34;, EscapeLDAPValue(username), cfg.UPNDomain)&lt;/p&gt;
&lt;p&gt;// Line 193 — User DN path
bindDN = fmt.Sprintf(&amp;#34;%s=%s,%s&amp;#34;, cfg.UserAttr, EscapeLDAPValue(username), cfg.UserDN)
```&lt;/p&gt;
&lt;p&gt;The problem: `EscapeLDAPValue()` implements **RFC 4514** escaping, which is designed for Distinguished Name (DN) components. It only escapes characters meaningful in DNs: `+`, `,`, `;`, `&amp;#34;`, `\`, `&amp;lt;`, `&amp;gt;`, and leading/trailing spaces.&lt;/p&gt;
&lt;p&gt;LDAP **search filters** (RFC 4515) have a different set of special characters: `*`, `(`, `)`, `\`, and NUL (`\x00`). None of these are escaped by `EscapeLDAPValue()`. The correct function is `ldap.EscapeFilter()` from the `github.com/go-ldap/ldap/v3` package.&lt;/p&gt;
&lt;p&gt;The irony: the same file uses `ldap.EscapeFilter()` correctly at lines 225-226 in `RenderUserSearchFilter()` for the `UserFilter` template path, but the `GetUserDN()` function at lines 191-193 uses the wrong escape function.&lt;/p&gt;
&lt;p&gt;### Exploitation Mechanics&lt;/p&gt;
&lt;p&gt;```
Username: alice)(objectClass=*
↓ EscapeLDAPValue (no-op — no DN special chars…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6mwx-4547-5vc9</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2028 — OpenBao: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2028</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenBao ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in OpenBao ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2028</guid>
    </item>
  </channel>
</rss>
