Skip to main content
QUIETLYTIC
Vulnerability

curl Authentication Bypass (CVE-2026-13608)

CVE-2026-13608 is a CVSS 7.4 high-severity flaw letting a man-in-the-middle attacker bypass libcurl SASL/LDAP authentication via an incomplete handshake.

CVE-2026-13608
Threat Level
HIGH
CVSS
7.4
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl

CVE-2026-13608 is a high-severity (CVSS 3.1 base 7.4) authentication-bypass flaw in libcurl’s SASL negotiation for LDAP authentication. As with CVE-2026-19931 and CVE-2026-18924, this appears in Microsoft’s own security-update data because Windows bundles libcurl — the actually affected project is curl, not Microsoft-authored code.

What the vulnerability does

Per curl’s own advisory, a flaw in libcurl’s SASL handshake logic for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker positioned as a man-in-the-middle can inject a premature or shortcut response that bypasses full peer validation — effectively tricking the client into believing authentication succeeded when the cryptographic exchange was never actually completed.

The CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) shows a network-reachable flaw with high attack complexity (an MITM position is required) needing no privileges or user interaction, with high confidentiality and integrity impact but no availability impact — consistent with an authentication bypass rather than a crash or resource-exhaustion bug.

What we don’t yet have

No public proof-of-concept or evidence of active exploitation is documented as of this writing, and CVE-2026-13608 is not listed in CISA’s KEV catalog. Confidence is medium — description and CVSS trace to NVD/curl’s advisory, but affected/fixed version ranges aren’t yet present in our ingested data.

Why this matters

The high attack complexity (a network position capable of intercepting and manipulating the connection) narrows real-world exploitability compared to a remote, unauthenticated bug, but any application using libcurl for LDAP authentication over an untrusted network path — corporate VPNs with compromised nodes, shared or hostile network segments — should still prioritize confirming their libcurl version once curl publishes the specific fixed release.

Frequently Asked Questions

What is CVE-2026-13608? A CVSS 7.4 high-severity vulnerability in libcurl allowing a man-in-the-middle attacker to bypass SASL/LDAP authentication via an incomplete handshake.

Is this a Microsoft vulnerability? No — it’s a libcurl (curl project) vulnerability that appears in Microsoft’s data because Windows bundles libcurl.

Is CVE-2026-13608 being actively exploited? Not as of this writing — it is not listed in CISA’s Known Exploited Vulnerabilities catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools