CVE-2026-24130: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-24130 is an LDAP search filter injection vulnerability in Moonraker, a Python web server providing API access to Klipper 3D printing firmware. Instances configured with the ldap component enabled are vulnerable via the login endpoint, where unsanitized username input is directly interpolated into LDAP search filter strings. The vulnerability affects Moonraker versions 0.9.3 and below (all versions prior to 0.10.0) and was disclosed on January 22, 2026. It carries a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 2.7 (Low) (GitHub Advisory).

Technical details

The root cause is improper neutralization of special elements in an LDAP query (CWE-90), compounded by error messages that leak query result information (CWE-209). In the vulnerable code within moonraker/components/ldap.py, the username supplied at the login endpoint was directly interpolated into the LDAP filter string — e.g., (&(objectClass=Person)(uid={username})) — without escaping LDAP special characters. An attacker can craft usernames containing LDAP filter metacharacters (such as *, (, ), \) to manipulate the search logic, and then use the presence or absence of a 401 error response to infer whether the injected filter matched any directory entries. The fix, applied in commit 74c5d8e, introduces escape_filter_chars() from ldap3.utils.conv to sanitize the username before substitution (Moonraker Commit, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to enumerate LDAP directory entries — including user IDs and user attributes — by performing blind injection via the login endpoint and analyzing 401 error responses. This constitutes a confidentiality impact against the LDAP directory, potentially exposing organizational user account information that could facilitate targeted credential attacks or further intrusion into authentication infrastructure. Integrity and availability of the Moonraker instance itself are not directly affected (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is exploitable by unauthenticated attackers over the network with low complexity, but only when the ldap component is explicitly enabled in the Moonraker configuration — a non-default setting. The EPSS score is approximately 0.047% (0.023% per GitHub Advisory), placing it in a low exploitation probability tier. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and reported by researcher solovvway (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Moonraker instances accessible over the network (default port 7125) using tools like Shodan or Censys. Confirm the instance is running version 0.9.3 or below and has the ldap component enabled (this may be inferred by observing LDAP-related error messages at the login endpoint).
  2. Probe the login endpoint: Send HTTP POST requests to the Moonraker login endpoint (e.g., /access/login) with crafted username values containing LDAP filter metacharacters.
  3. Inject filter characters: Use payloads such as *)(uid=*))(|(uid=* or similar LDAP filter injection strings in the username field to manipulate the constructed filter (&(objectClass=Person)(uid={username})).
  4. Analyze error responses: Observe whether the server returns a 401 response indicating a failed search (no match) versus a different response indicating a successful LDAP lookup. Use this boolean oracle to infer directory structure.
  5. Enumerate directory entries: Iteratively refine injected filters to brute-force valid user IDs and attributes (e.g., using character-by-character enumeration: a*, b*, etc.) by automating requests and correlating 401 response patterns.
  6. Leverage discovered data: Use enumerated usernames and attributes to conduct targeted password attacks or further reconnaissance against the organization's authentication infrastructure (GitHub Advisory, Moonraker Commit).

Indicators of compromise

  • Network: High volume of HTTP POST requests to the Moonraker login endpoint (e.g., /access/login) from a single IP address, particularly with unusual or malformed username values containing LDAP special characters (*, (, ), \, NUL).
  • Logs: Moonraker access logs showing repeated 401 responses to the login endpoint in rapid succession from the same source IP; log entries containing usernames with LDAP metacharacters or wildcard patterns.
  • Logs: LDAP server logs showing a high volume of search queries with unusual filter expressions originating from the Moonraker service account, particularly filters containing wildcard or injection patterns.
  • Process/Application: Moonraker application logs indicating repeated authentication failures with structurally unusual username strings that do not resemble normal user input.

Mitigation and workarounds

Users should upgrade Moonraker to version 0.10.0 or later, which resolves the vulnerability by escaping LDAP filter special characters from the username before query construction (GitHub Advisory). For those unable to upgrade immediately, two workarounds are available: (1) set the max_login_attempts option in the [authorization] section of moonraker.conf to a low value to lock out IPs after repeated failed attempts (note: this can be bypassed if the attacker knows a valid password); or (2) remove the [ldap] section from moonraker.conf entirely and rely on Moonraker's built-in user authentication. Additionally, restricting network access to the Moonraker login endpoint to trusted networks only reduces exposure (Moonraker Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management