Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-5050-Blind-LDAP-Injection-via-Unescaped-Filter — Reproduces CVE-2026-5050 with a simulated Flask LDAP server and exploit script, demonstrating blind LDAP injection via unescaped filters to bypass authentication and enumerate users. | Kitploit
Tools/GitHubGitHub/george0papasotiriou/cve-2026-5050-blind-ldap-injection-via-unescaped-filter
Vulnerability AnalysisExploitationWeb Application ExploitationAuthenticationLearning & Education
GitHubgeorge0papasotiriou/cve-2026-5050-blind-ldap-injection-via-unescaped-filter

CVE-2026-5050-Blind-LDAP-Injection-via-Unescaped-Filter

Reproduces CVE-2026-5050 with a simulated Flask LDAP server and exploit script, demonstrating blind LDAP injection via unescaped filters to bypass authentication and enumerate users.

View Repository
31 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-5050 – Blind LDAP Injection via Unescaped Filter

Program Code (Python with ldap3 simulation)

root@kitploit:~
# ldap_server_sim.py - Simulated LDAP authentication server
from flask import Flask, request, jsonify

app = Flask(__name__)

# Fake user database
USERS = {
    'admin': {'password': 'secret', 'role': 'admin'},
    'user': {'password': 'pass', 'role': 'user'}
}

def ldap_search(username, password):
    # Simulate an LDAP filter injection: user-controlled username goes directly into filter
    # Real LDAP query: (&(uid={username})(userPassword={password}))
    # Here we just simulate: if the username contains wildcard, it may bypass.
    if '*' in username:
        # Vulnerability: filter becomes (uid=*) which matches any user
        # We'll return the first matching user (admin)
        return USERS.get('admin')
    return USERS.get(username)

@app.route('/login', methods=['POST'])
def login():
    username = request.form.get('username')
    password = request.form.get('password')
    user = ldap_search(username, password)
    if user and user['password'] == password:
        return jsonify({"message": "Authenticated", "role": user['role']})
    return jsonify({"message": "Invalid"}), 401

if __name__ == '__main__':
    app.run(port=5000)

CVE-2026-5050 – Blind LDAP Injection via Unescaped Filter

Severity: High

Overview

An authentication system constructs an LDAP search filter by directly concatenating user input without escaping special characters. An attacker can inject wildcards (*) to bypass authentication or enumerate users.

Vulnerability Details

  • Type: LDAP Injection
  • Impact: Authentication bypass, information disclosure.
  • Root Cause: The username parameter is not sanitised, allowing characters like *, (, ) to modify the LDAP filter logic.

Exploit Demonstration

  1. Start the simulated vulnerable server:
    root@kitploit:~
    pip install flask
    python ldap_server_sim.py
    
  2. Run the exploit:
    root@kitploit:~
    python exploit_ldap_injection.py
    
Download Tool