CVE-2026-0636: LDAP Injection Vulnerability in LDAPStoreHelper.java
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).
This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Other sources
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.84.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0636?
CVE-2026-0636 has a severity rating that indicates a medium risk due to potential LDAP injection attacks.
How do I fix CVE-2026-0636?
To fix CVE-2026-0636, update your Bouncy Castle BC-JAVA bcprov library to a version above 1.84.
What is LDAP injection in the context of CVE-2026-0636?
LDAP injection in the context of CVE-2026-0636 refers to the improper handling of user input in LDAP queries, allowing malicious input to alter query execution.
Which versions of Bouncy Castle BC-JAVA bcprov are affected by CVE-2026-0636?
CVE-2026-0636 affects Bouncy Castle BC-JAVA bcprov versions from 1.49 to 1.84.
What are the consequences of not addressing CVE-2026-0636?
Failing to address CVE-2026-0636 can lead to unauthorized access or manipulation of LDAP data, compromising application security.