CVE-2026-81205: Miniorange LDAP / Active Directory Integration

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

Affected products

  • Miniorange LDAP / Active Directory Integration: from 2.0.1, before 2.2.1 (fixed in 2.2.1); from 7.x-1.0, up to and including 7.x-1.21; from 8.x-1.0, up to and including 8.x-1.34

Published 2026-09-02. Last modified 2026-09-16.