---
id: CVE-2026-81205
title: >-
  Improper Neutralization of Special Elements used in an LDAP Query ('LDAP
  Injection') vulnerability in Drupal LDAP / Active Directory Integration allows
  LDAP Injection
summary: >-
  Improper Neutralization of Special Elements used in an LDAP Query ('LDAP
  Injection') vulnerability in Drupal LDAP / Active Directory Integration allows
  LDAP Injection. This issue affects LDAP / Active Directory Integration
  versions: from…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-90
vendor: miniorange
product: ldap_/_active_directory_integration
affected:
  - 'ldap_/_active_directory_integration >= 2.0.1, < 2.2.1'
  - 'ldap_/_active_directory_integration >= 7.x-1.0, <= 7.x-1.21'
  - 'ldap_/_active_directory_integration >= 8.x-1.0, <= 8.x-1.34'
patched:
  - ldap_/_active_directory_integration 2.2.1
published: '2026-09-02'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:43:37.810'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81205'
references:
  - url: 'https://www.drupal.org/sa-contrib-2026-115'
    label: mlhess@drupal.org
tags:
  - nvd
epss: 0.00334
epssPercentile: 0.24034
ingestedAt: '2026-09-16T15:58:38.723Z'
---

## Overview

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

## Affected

- `ldap_/_active_directory_integration >= 2.0.1, < 2.2.1`
- `ldap_/_active_directory_integration >= 7.x-1.0, <= 7.x-1.21`
- `ldap_/_active_directory_integration >= 8.x-1.0, <= 8.x-1.34`

## Remediation

Upgrade past the affected range:

- `ldap_/_active_directory_integration 2.2.1`
