A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. (CVE-2026-74241)
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle attacks at the referral Directory Name (DN). This could also potentially influence which DN is used for password binding in multi-domain Active Directory environments.
AI Analysis
Technical Summary
CVE-2026-74241 is a vulnerability in Red Hat Quay's external LDAP authentication mechanism. When an LDAP referral is returned during authentication, the system fails to properly escape the username input, allowing an attacker to inject LDAP filter metacharacters. This improper neutralization of special elements (CWE-90) enables user-existence oracle attacks against the referral DN and may affect password binding selection in multi-domain Active Directory setups. The vulnerability has a CVSS 3.1 base score of 4.8 (medium severity) with network attack vector, high attack complexity, no privileges required, and no user interaction. Red Hat has not released a patch or official fix yet, citing lack of suitable mitigation options that meet their criteria for ease of use, applicability, and stability.
Potential Impact
The vulnerability allows an attacker to perform user-existence oracle attacks by injecting LDAP filter metacharacters during referral processing in LDAP authentication. This can reveal information about valid users in the directory. Additionally, it may influence which Directory Name is used for password binding in multi-domain Active Directory environments. However, direct authentication bypass is not possible, and directory enumeration is limited. The overall confidentiality and integrity impact is low, with no availability impact.
Mitigation Recommendations
Currently, there is no official fix or patch available from Red Hat that meets their criteria for deployment and stability. Red Hat advises monitoring their advisory for updates. No specific mitigations are provided, and users should be aware of the potential for user-existence oracle attacks. Customers with Red Hat Technical Account Managers (TAM) can consult directly for guidance. It is recommended to follow Red Hat's official channels for any future patches or mitigations.
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. (CVE-2026-74241)
Description
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle attacks at the referral Directory Name (DN). This could also potentially influence which DN is used for password binding in multi-domain Active Directory environments.
CVSS v3.1
Score 4.8medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-74241 is a vulnerability in Red Hat Quay's external LDAP authentication mechanism. When an LDAP referral is returned during authentication, the system fails to properly escape the username input, allowing an attacker to inject LDAP filter metacharacters. This improper neutralization of special elements (CWE-90) enables user-existence oracle attacks against the referral DN and may affect password binding selection in multi-domain Active Directory setups. The vulnerability has a CVSS 3.1 base score of 4.8 (medium severity) with network attack vector, high attack complexity, no privileges required, and no user interaction. Red Hat has not released a patch or official fix yet, citing lack of suitable mitigation options that meet their criteria for ease of use, applicability, and stability.
Potential Impact
The vulnerability allows an attacker to perform user-existence oracle attacks by injecting LDAP filter metacharacters during referral processing in LDAP authentication. This can reveal information about valid users in the directory. Additionally, it may influence which Directory Name is used for password binding in multi-domain Active Directory environments. However, direct authentication bypass is not possible, and directory enumeration is limited. The overall confidentiality and integrity impact is low, with no availability impact.
Mitigation Recommendations
Currently, there is no official fix or patch available from Red Hat that meets their criteria for deployment and stability. Red Hat advises monitoring their advisory for updates. No specific mitigations are provided, and users should be aware of the potential for user-existence oracle attacks. Customers with Red Hat Technical Account Managers (TAM) can consult directly for guidance. It is recommended to follow Red Hat's official channels for any future patches or mitigations.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x5cw-v6mp-3p93
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74241"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7ff5e6bf8831d53987df56
Added to database: 08/15/2026, 05:15:18 UTC
Last enriched: 08/15/2026, 06:14:34 UTC
Last updated: 08/15/2026, 20:41:01 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.