{"id":"CVE-2021-38266","title":"The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent …","summary":"The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"liferay","product":"liferay_portal","affected":["liferay_portal <= 7.2.1","digital_experience_platform = 7.0","digital_experience_platform = 7.1","digital_experience_platform = 7.2"],"published":"2022-03-02","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-38266","references":[{"url":"https://issues.liferay.com/browse/LPE-17191","label":"cve@mitre.org"},{"url":"https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38266","label":"cve@mitre.org"},{"url":"http://liferay.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://issues.liferay.com/browse/LPE-17191","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38266","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01742,"epssPercentile":0.76752,"ingestedAt":"2026-07-06T17:03:23.919Z","slug":"CVE-2021-38266","body":"## Overview\n\nThe Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.\n\n## Affected\n\n- `liferay_portal <= 7.2.1`\n- `digital_experience_platform = 7.0`\n- `digital_experience_platform = 7.1`\n- `digital_experience_platform = 7.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}