LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115

Project: LDAP / Active Directory IntegrationDate: 2026-August-26Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Proof/TD:AllVulnerability: Information DisclosureAffected versions: <2.2.1CVE IDs: CVE-2026-81205Description: This module enables users to authenticate using LDAP or Active Directory credentials.
The module does not sufficiently sanitize user-supplied input before incorporating it into an LDAP search filter. This allows an attacker to discover additional information they should not normally be able to. Solution: Install the latest version:

Reported By: 

Fixed By: 

Coordinated By: 

Path to article https://www.drupal.org/sa-contrib-2026-115