216.73.216.6

CVE-2026-27895

· Published 18/03/2026 00:16 · Modified 18/03/2026 14:52

Labels: CVE-2026-27895 2026-03-18CVE-2026-27895CWE-185[email protected]

Essential information

Published
18/03/2026 00:16
Modified
18/03/2026 14:52
Author
Creator
CVSS
4.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CVSS metrics

Description

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ldap account manager / ldap account manager cpe:2.3:a:ldap_account_manager:ldap_account_manager:<9.5:*:*:*:*:*:*:*

References