LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-27895

ldap-account-manager · ldap account manager

Published
CVSS4.3
Severitymedium
WeaknessCWE-185
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-27895

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-27895.