A vulnerability was found in bestpractical rt up to 5.0.9/6.0.2 . It has been declared as critical . The affected element is an unknown function of the component LDAP/AD . Such manipulation leads to improper authentication. This vulnerability is traded as CVE-2026-41076 . The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.