
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24130 is an LDAP search filter injection vulnerability in Moonraker, a Python web server providing API access to Klipper 3D printing firmware. Instances configured with the ldap component enabled are vulnerable via the login endpoint, where unsanitized username input is directly interpolated into LDAP search filter strings. The vulnerability affects Moonraker versions 0.9.3 and below (all versions prior to 0.10.0) and was disclosed on January 22, 2026. It carries a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 2.7 (Low) (GitHub Advisory).
The root cause is improper neutralization of special elements in an LDAP query (CWE-90), compounded by error messages that leak query result information (CWE-209). In the vulnerable code within moonraker/components/ldap.py, the username supplied at the login endpoint was directly interpolated into the LDAP filter string — e.g., (&(objectClass=Person)(uid={username})) — without escaping LDAP special characters. An attacker can craft usernames containing LDAP filter metacharacters (such as *, (, ), \) to manipulate the search logic, and then use the presence or absence of a 401 error response to infer whether the injected filter matched any directory entries. The fix, applied in commit 74c5d8e, introduces escape_filter_chars() from ldap3.utils.conv to sanitize the username before substitution (Moonraker Commit, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to enumerate LDAP directory entries — including user IDs and user attributes — by performing blind injection via the login endpoint and analyzing 401 error responses. This constitutes a confidentiality impact against the LDAP directory, potentially exposing organizational user account information that could facilitate targeted credential attacks or further intrusion into authentication infrastructure. Integrity and availability of the Moonraker instance itself are not directly affected (GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is exploitable by unauthenticated attackers over the network with low complexity, but only when the ldap component is explicitly enabled in the Moonraker configuration — a non-default setting. The EPSS score is approximately 0.047% (0.023% per GitHub Advisory), placing it in a low exploitation probability tier. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and reported by researcher solovvway (GitHub Advisory).
ldap component enabled (this may be inferred by observing LDAP-related error messages at the login endpoint)./access/login) with crafted username values containing LDAP filter metacharacters.*)(uid=*))(|(uid=* or similar LDAP filter injection strings in the username field to manipulate the constructed filter (&(objectClass=Person)(uid={username})).a*, b*, etc.) by automating requests and correlating 401 response patterns./access/login) from a single IP address, particularly with unusual or malformed username values containing LDAP special characters (*, (, ), \, NUL).Users should upgrade Moonraker to version 0.10.0 or later, which resolves the vulnerability by escaping LDAP filter special characters from the username before query construction (GitHub Advisory). For those unable to upgrade immediately, two workarounds are available: (1) set the max_login_attempts option in the [authorization] section of moonraker.conf to a low value to lock out IPs after repeated failed attempts (note: this can be bypassed if the attacker knows a valid password); or (2) remove the [ldap] section from moonraker.conf entirely and rely on Moonraker's built-in user authentication. Additionally, restricting network access to the Moonraker login endpoint to trusted networks only reduces exposure (Moonraker Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."