PT-2026-25966 · Unknown · Ldap Account Manager

Jonaslejon

·

Published

2026-03-17

·

Updated

2026-03-19

·

CVE-2026-27895

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LDAP Account Manager versions prior to 9.5
Description LDAP Account Manager (LAM) is a web frontend used for managing entries in an LDAP directory, such as users, groups, and DHCP settings. Before version 9.5, the PDF export component does not properly validate file extensions during file uploads, allowing any file type, including .php files, to be uploaded. This can lead to remote code execution as the web server user. The vulnerable component allows an attacker to upload malicious files, potentially compromising the system.
Recommendations Versions prior to 9.5 should be upgraded to version 9.5 or later. As a workaround, make the /var/lib/ldap-account-manager/config directory read-only for the web server user.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27895
GHSA-88HF-2CJM-M9G8
GHSA-W7XQ-VJR3-P9CF

Affected Products

Ldap Account Manager