Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. (CVE-2026-74241)

0
Medium
Published: 08/15/2026 (08/15/2026, 00:31:24 UTC)
Source: GCVE Database

Description

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle attacks at the referral Directory Name (DN). This could also potentially influence which DN is used for password binding in multi-domain Active Directory environments.

CVSS v3.1

Score 4.8medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 06:14:34 UTC

Technical Analysis

CVE-2026-74241 is a vulnerability in Red Hat Quay's external LDAP authentication mechanism. When an LDAP referral is returned during authentication, the system fails to properly escape the username input, allowing an attacker to inject LDAP filter metacharacters. This improper neutralization of special elements (CWE-90) enables user-existence oracle attacks against the referral DN and may affect password binding selection in multi-domain Active Directory setups. The vulnerability has a CVSS 3.1 base score of 4.8 (medium severity) with network attack vector, high attack complexity, no privileges required, and no user interaction. Red Hat has not released a patch or official fix yet, citing lack of suitable mitigation options that meet their criteria for ease of use, applicability, and stability.

Potential Impact

The vulnerability allows an attacker to perform user-existence oracle attacks by injecting LDAP filter metacharacters during referral processing in LDAP authentication. This can reveal information about valid users in the directory. Additionally, it may influence which Directory Name is used for password binding in multi-domain Active Directory environments. However, direct authentication bypass is not possible, and directory enumeration is limited. The overall confidentiality and integrity impact is low, with no availability impact.

Mitigation Recommendations

Currently, there is no official fix or patch available from Red Hat that meets their criteria for deployment and stability. Red Hat advises monitoring their advisory for updates. No specific mitigations are provided, and users should be aware of the potential for user-existence oracle attacks. Customers with Red Hat Technical Account Managers (TAM) can consult directly for guidance. It is recommended to follow Red Hat's official channels for any future patches or mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-x5cw-v6mp-3p93
Osv Schema Version
1.4.0
Aliases
["CVE-2026-74241"]
Ecosystems
[]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a7ff5e6bf8831d53987df56

Added to database: 08/15/2026, 05:15:18 UTC

Last enriched: 08/15/2026, 06:14:34 UTC

Last updated: 08/15/2026, 20:41:01 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses