PT-2026-25966 · Unknown · Ldap Account Manager

Jonaslejon

·

Publicado

2026-03-17

·

Atualizado

2026-03-19

·

CVE-2026-27895

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LDAP Account Manager versions prior to 9.5
Description LDAP Account Manager (LAM) is a web frontend used for managing entries in an LDAP directory, such as users, groups, and DHCP settings. Before version 9.5, the PDF export component does not properly validate file extensions during file uploads, allowing any file type, including .php files, to be uploaded. This can lead to remote code execution as the web server user. The vulnerable component allows an attacker to upload malicious files, potentially compromising the system.
Recommendations Versions prior to 9.5 should be upgraded to version 9.5 or later. As a workaround, make the /var/lib/ldap-account-manager/config directory read-only for the web server user.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27895
GHSA-88HF-2CJM-M9G8
GHSA-W7XQ-VJR3-P9CF

Produtos afetados

Ldap Account Manager