GHSA-5hmm-x8q8-w5jh · Severity: critical · Ecosystem: pip — LDAP authentication bypass with empty password
In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP servers are configured to allow unauthenticated authentication mechanism for anonymous authorization are affected. A fix has been implemented in version 8.1.0 that returns HTTP 401 Unauthorized response for any authentication attempts where the password field is empty. As a workaround LDAP administrators can disallow unauthenticated bind requests by clients.
Conclusion & alert: CVE-2020-26214 is rated High Risk (71.7/100): CVSS Critical severity, with high exploitation likelihood (EPSS 65.93%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-20 | 65.34% | 65.93% | +0.59% |
| 2 | 2026-06-15 | 88.89% | 65.34% | -23.54% |
| 3 | 2026-04-10 | — | 88.89% | — |
Full EPSS history (36 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-5hmm-x8q8-w5jh · Severity: critical · Ecosystem: pip — LDAP authentication bypass with empty password
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| alerta_project | alerta | < 7.5.7 | cpe:2.3:a:alerta_project:alerta:*:*:*:*:*:*:*:* |
| alerta_project | alerta | >= 8.0.0, < 8.1.0 | cpe:2.3:a:alerta_project:alerta:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/alerta/alerta/commit/2bfa31779a4c9df2fa68fa4d0c5c909698c5ef65 | Patch Third Party Advisory |
| https://github.com/alerta/alerta/issues/1277 | Third Party Advisory |
| https://github.com/alerta/alerta/pull/1345 | Third Party Advisory |
| https://github.com/alerta/alerta/security/advisories/GHSA-5hmm-x8q8-w5jh | Third Party Advisory |
| https://pypi.org/project/alerta-server/8.1.0/ | Third Party Advisory |
| https://tools.ietf.org/html/rfc4513#section-5.1.2 | Third Party Advisory |