CVE-2020-26168
NixOS vulnerability analysis and mitigation

Overview

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, contained a vulnerability where the system didn't properly verify passwords in certain system-user-dn scenarios. This authentication bypass vulnerability was discovered and disclosed in November 2020 (Debian Tracker).

Technical details

The vulnerability exists in the LDAP authentication implementation where the password verification process was flawed. Specifically, in certain system-user-dn scenarios, the LdapLoginModule failed to properly validate user passwords during the authentication process (Hazelcast Docs).

Impact

The vulnerability allowed users (clients/members) to be authenticated even when providing invalid passwords, effectively bypassing the authentication mechanism. This could potentially lead to unauthorized access to the Hazelcast cluster (Debian Tracker).

Exploitability

The vulnerability could be exploited by attempting to authenticate with invalid credentials in specific system-user-dn scenarios, potentially allowing unauthorized access to the system (Debian Tracker).

Mitigation and workarounds

The vulnerability was addressed in Hazelcast IMDG Enterprise version 4.0.3. Users running affected versions should upgrade to version 4.0.3 or later to resolve this security issue (Hazelcast Docs).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86993MEDIUM5.9
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86996MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86995MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86994MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86085MEDIUM5.1
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management