CVE-2026-41076

개요

A flaw was found in RT, an open-source issue and ticket tracking system. This vulnerability allows a remote attacker to bypass authentication in RT installations configured to use LDAP/AD (Lightweight Directory Access Protocol/Active Directory) for user authentication. Under specific LDAP server configurations, an attacker can authenticate as any legitimate LDAP-backed RT user without providing valid credentials, leading to unauthorized access to the system.

내용

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

취약점 이해 (CWE)

Integrity,Confidentiality,Availability,Access Control

Technical Impact: Read Application Data; Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands

This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

자주하는 질문

에라타 알림을 받으시겠습니까? 여기에서 등록하세요.