Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-23906

Apache Druid: LDAP authentication bypass through anonymous bind

Technology

Apache Druid

CVSS Score

9.8 / 10.0

Affected Versions

Apache Druid 0.17.0 to 35.x, with druid-basic-security and an LDAP authenticator

Upstream Fix

36.0.0

Published

February 10, 2026

OSSeva Coverage

Fixed upstream

Description

When Druid uses the druid-basic-security extension with an LDAP authenticator and the LDAP server permits anonymous bind, an attacker can log in with an existing username and an empty password, because Druid treats a successful anonymous bind as valid authentication. Disabling anonymous bind on the LDAP server prevents it without a Druid upgrade.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid 0.17.0 to 35.x, with druid-basic-security and an LDAP authenticator, you need this patch. Book a discovery call to get covered.