Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://ydb.tech/docs/ru/security-changelog |
|
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yandex
Yandex yandex Database |
|
| Vendors & Products |
Yandex
Yandex yandex Database |
Tue, 02 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database. | |
| Title | Privilege escalation in Yandex Database | |
| Weaknesses | CWE-280 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: yandex
Published:
Updated: 2026-06-02T13:30:02.360Z
Reserved: 2026-06-01T13:30:40.384Z
Link: CVE-2026-10549
Updated: 2026-06-02T13:29:53.631Z
Status : Deferred
Published: 2026-06-02T10:16:20.357
Modified: 2026-06-02T14:45:28.410
Link: CVE-2026-10549
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:51:46Z