CVE-2026-14474: Ldap Search Base Root Dn Fallback

Unconfigured LDAP search base falls back to root naming context without logging or restriction. Searching the entire directory root DN for privileged objects like sudo roles allows any user with write access to any LDAP subtree to inject rules and elevate privileges.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-14474-ldap-search-base-root-dn-fallback --engine opengrep

Description

Unconfigured LDAP search base falls back to root naming context without logging or restriction. Searching the entire directory root DN for privileged objects like sudo roles allows any user with write access to any LDAP subtree to inject rules and elevate privileges.