CVE-2026-27895

medium

Description

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.

References

https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-w7xq-vjr3-p9cf

https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-88hf-2cjm-m9g8

https://github.com/LDAPAccountManager/lam/releases/tag/9.5

Details

Source: Mitre, NVD

Published: 2026-03-18

Updated: 2026-03-18

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00062