CVE-2026-27895
Last modified
CVE-2026-27895 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ldap-Account-Manager | Ldap Account Manager | >= 8.5, < 9.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27895?
How severe is CVE-2026-27895?
How do I fix CVE-2026-27895?
Are you affected by CVE-2026-27895?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
