CVE-2026-23906
Apache Druid: LDAP authentication bypass through anonymous bind
Technology
Apache Druid
CVSS Score
9.8 / 10.0
Affected Versions
Apache Druid 0.17.0 to 35.x, with druid-basic-security and an LDAP authenticator
Upstream Fix
36.0.0
Published
February 10, 2026
OSSeva Coverage
Fixed upstream
Description
When Druid uses the druid-basic-security extension with an LDAP authenticator and the LDAP server permits anonymous bind, an attacker can log in with an existing username and an empty password, because Druid treats a successful anonymous bind as valid authentication. Disabling anonymous bind on the LDAP server prevents it without a Druid upgrade.
Is your Apache Druid deployment affected?
If you're running Apache Druid 0.17.0 to 35.x, with druid-basic-security and an LDAP authenticator, you need this patch. Book a discovery call to get covered.