PT-2026-25963 · Unknown · Ldap Account Manager

Jonaslejon

·

Published

2026-03-17

·

Updated

2026-03-19

·

CVE-2026-27894

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LDAP Account Manager versions prior to 9.5
Description LDAP Account Manager (LAM) is a web interface used to manage entries in an LDAP directory, such as users, groups, and DHCP settings. A local file inclusion issue was identified in the PDF export functionality in versions prior to 9.5. This allows users to include local PHP files and execute code. Exploitation requires a user to be logged into LAM. Combining this with another issue allows for arbitrary code execution.
Recommendations Versions prior to 9.5 should be upgraded to version 9.5. As a workaround, make the /var/lib/ldap-account-manager/config directory read-only for the web server user. Delete the PDF profile files to disable PDF exports.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27894
GHSA-88HF-2CJM-M9G8
GHSA-W7XQ-VJR3-P9CF

Affected Products

Ldap Account Manager