BaseDraft

CWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Category: injection

Description

The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

Common consequences· 1

  • Confidentiality / Integrity / Availability — Execute Unauthorized Code or Commands, Read Application Data, Modify Application Data
    An attacker could include input that changes the LDAP query which allows unintended commands or code to be executed, allows sensitive data to be read or modified or causes other unintended behavior.

Potential mitigations· 1

  • [Implementation]

Related CAPEC attack patterns· 1

CAPEC-136

References

  1. https://cwe.mitre.org/data/definitions/90.html

Exploits (incoming)1

TypeTargetConfidenceTier
AttackPatternLDAP Injectioncapec-136100%live

Compliance frameworks addressing this (incoming)1

TypeTargetConfidenceTier
ComplianceControlowasp_top10-a03100%live

(incoming)12

TypeTargetConfidenceTier
VulnerabilityCVE-2025-48208cve-2025-482080%live
VulnerabilityCVE-2025-67493cve-2025-674930%live
VulnerabilityCVE-2026-25560cve-2026-255600%live
VulnerabilityCVE-2026-31828cve-2026-318280%live
VulnerabilityCVE-2026-33289cve-2026-332890%live
VulnerabilityCVE-2026-34578cve-2026-345780%live
VulnerabilityCVE-2026-39962cve-2026-399620%live
VulnerabilityCVE-2026-40193cve-2026-401930%live
VulnerabilityCVE-2026-40459cve-2026-404590%live
VulnerabilityCVE-2026-41919cve-2026-419190%live
VulnerabilityCVE-2026-44304cve-2026-443040%live
VulnerabilityCVE-2026-44930cve-2026-449300%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE
Improper Neutralization of Data within XQuery Expressions ('XQuery Injection')
CWE
Improper Neutralization of Data within XPath Expressions ('XPath Injection')
CWE
Improper Neutralization of Internal Special Elements
CWE
Improper Neutralization of Multiple Internal Special Elements
CWE
Improper Neutralization of Wildcards or Matching Symbols
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.