CVE-2020-26542
Last modified
CVE-2020-26542 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deployed at the level granted to the authenticating account.. EPSS estimates a 1.52% chance of exploitation in the next 30 days.
Description
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deployed at the level granted to the authenticating account.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Percona | Percona Server | <= 2020-10-02 |
References
- https://jira.percona.com/browse/PS-7358Issue Tracking, Permissions Required, Vendor Advisory
- https://jira.percona.com/browse/PSMDB-726Issue Tracking, Permissions Required, Vendor Advisory
- https://www.percona.com/doc/percona-distribution-mysql/8.0/release-notes-pxc-v8.0.20.upd2.htmlRelease Notes, Vendor Advisory
- https://jira.percona.com/browse/PS-7358Issue Tracking, Permissions Required, Vendor Advisory
- https://jira.percona.com/browse/PSMDB-726Issue Tracking, Permissions Required, Vendor Advisory
- https://www.percona.com/doc/percona-distribution-mysql/8.0/release-notes-pxc-v8.0.20.upd2.htmlRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-26542?
How severe is CVE-2020-26542?
How do I fix CVE-2020-26542?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-26537An issue was discovered in Foxit Reader and PhantomPDF befor…9.8
- CVE-2020-26538An issue was discovered in Foxit Reader and PhantomPDF befor…7.8
- CVE-2020-26539An issue was discovered in Foxit Reader and PhantomPDF befor…9.8
- CVE-2020-2654Vulnerability in the Java SE product of Oracle Java SE (comp…3.7
- CVE-2020-26540An issue was discovered in Foxit Reader and PhantomPDF befor…7.5
- CVE-2020-26541The Linux kernel through 5.8.13 does not properly enforce th…6.5
- CVE-2020-26546An issue was discovered in HelpDeskZ 1.0.2. The feature to a…7.5
- CVE-2020-26547Monal before 4.9 does not implement proper sender verificati…9.8
- CVE-2020-26548An issue was discovered in Aviatrix Controller before R5.4.1…8.8
- CVE-2020-26549An issue was discovered in Aviatrix Controller before R5.4.1…7.5
- CVE-2020-2655Vulnerability in the Java SE product of Oracle Java SE (comp…4.8
- CVE-2020-26550An issue was discovered in Aviatrix Controller before R5.3.1…7.5
Are you affected by CVE-2020-26542?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
