Search/CVE-2026-10549
CVE

CVE-2026-10549

LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database.

CVSS v3.1
EPSS
0.27%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
1 relationships
Timeline
disclosure → media coverage
Jun 2, 2026
Disclosure — published as a CVE record. · last revised by NVD Jul 22, 2026